CVE-2022-2565

CVE-2022-2565: Best Payments Plugin for WP < 4.2.1 - Unauthenticated Stored Cross-Site Scripting

Vendor Unknown
Product Simple Payment Donations & Subscriptions Plugin by Paymattic – Best Payments Plugin for WP
Weakness CWE-79 · XSS
Published September 5, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Simple Payment Donations & Subscriptions WordPress plugin before 4.2.1 does not sanitise and escape user input given in its forms, which could allow unauthenticated attackers to perform Cross-Site Scripting attacks against admins

Key dates

02Disclosure timeline

September 5, 2022 CVE published
August 3, 2024 Record updated