CVE-2022-4946

CVE-2022-4946: Frontend Post WordPress Plugin <= 2.8.4 - Contributor+ Arbitrary Redirect

Vendor Unknown
Product Frontend Post WordPress Plugin
Published June 5, 2023
Last update January 8, 2025

CVSS base score

What the vulnerability does

01Description

The Frontend Post WordPress Plugin WordPress plugin through 2.8.4 does not validate an attribute of one of its shortcode, which could allow users with a role as low as contributor to add a malicious shortcode to a page/post, which will redirect users to an arbitrary domain.

Key dates

02Disclosure timeline

June 5, 2023 CVE published
January 8, 2025 Record updated