CVE-2022-3096

CVE-2022-3096: WP Total Hacks <= 4.7.2 - Subscriber+ Arbitrary Options Update to Stored XSS

Vendor Unknown
Product WP Total Hacks
Weakness CWE-862 · Missing authorization
Published October 31, 2022
Last update May 6, 2025

CVSS base score

What the vulnerability does

01Description

The WP Total Hacks WordPress plugin through 4.7.2 does not prevent low privilege users from modifying the plugin's settings. This could allow users such as subscribers to perform Stored Cross-Site Scripting attacks against other users, like administrators, due to the lack of sanitisation and escaping as well.

Key dates

02Disclosure timeline

October 31, 2022 CVE published
May 6, 2025 Record updated

Related vulnerabilities

04Related CVE