CyberRota
Live Feed
Return to register
Case File

CVE-2022-2425

MEDIUM · CVSS 4.8 EPSS 0.51%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-08-08 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2022-2425
Severity
MEDIUM
CVSS
4.8
EPSS
0.51%
WordPress

Original Filing — NVD Description

The WP DS Blog Map WordPress plugin through 3.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)