CVE-2022-23979 MEDIUM

CVE-2022-23979: WordPress Ultimate Reviews plugin <= 3.0.15 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

Vendor N/A
Product n/a
Published January 28, 2022
Last update April 28, 2026

CVSS base score

4.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability discovered in Ultimate Reviews WordPress plugin (versions <= 3.0.15).

Explanation of Vulnerability in Simple Terms

02Summary

A vulnerability in an unspecified product allows a high-privilege user to modify limited data on the site when they visit a malicious page. The attacker cannot read sensitive information or disrupt service, but can alter content if a site administrator is tricked into clicking a link. The scope extends beyond the vulnerable component itself.

What an attacker can do

03Attacker Capabilities

Modify limited data on the site if a high-privilege user visits a malicious page.

Potential impact on your site

04Site Impact

A compromised admin account or social engineering could allow unauthorized changes to site content or settings.

Conditions required to exploit

05Prerequisites

High-privilege account (e.g., administrator) and user interaction (victim must visit attacker's page).

Key dates

06Disclosure timeline

January 28, 2022 CVE published
April 28, 2026 Record updated