CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.8. It affects WordPress, Java.
CVE
CVE-2022-1995
Severity
MEDIUM
CVSS
4.8
EPSS
0.56%
WordPress Java
Original NVD Description
The Malware Scanner WordPress plugin before 4.5.2 does not sanitise and escape some of its settings, leading to malicious users with administrator privileges to store malicious Javascript code leading to Cross-Site Scripting attacks when unfiltered_html is disallowed (for example in multisite setup)
Related CVEs
Other vulnerabilities affecting the same vendor(s)