CVE-2022-44735 MEDIUM

CVE-2022-44735: WordPress WP Clictracker Plugin <= 1.0.5 is vulnerable to Cross Site Scripting (XSS)

Vendor Gus Sevilla
Product WP Clictracker
Weakness CWE-79 · XSS
Published April 18, 2023
Last update April 28, 2026

CVSS base score

4.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

What the vulnerability does

01Description

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.

Explanation of Vulnerability in Simple Terms

02Summary

WP Clictracker versions up to 1.0.5 contain a cross-site scripting (XSS) vulnerability that allows authenticated users with high privileges to inject malicious scripts. The vulnerability requires user interaction to trigger. An attacker with admin or editor access can craft a malicious link that, when clicked by another user, executes JavaScript in their browser session, potentially compromising their account or stealing sensitive data.

What an attacker can do

03Attacker Capabilities

Inject JavaScript code that runs in other users' browsers when they click a malicious link.

Potential impact on your site

04Site Impact

A malicious admin or editor can steal session tokens or credentials from other users, or deface site content.

Conditions required to exploit

05Prerequisites

Attacker must have high-level site privileges (admin/editor). Victim must click the attacker's crafted link.

Key dates

06Disclosure timeline

April 18, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE