CVE-2022-3137

All FrameworksWordPressCWE-79CVE-2022-3137

CVE-2022-3137

State: PUBLISHED · Published: 2022-10-10 · Updated: 2024-08-03 · Assigner: WPScan
Description
The Taskbuilder WordPress plugin before 1.0.8 does not validate and sanitise task's attachments, which could allow any authenticated user (such as subscriber) creating a task to perform Stored Cross-Site Scripting by attaching a malicious SVG file
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2022/3xxx/CVE-2022-3137.json