← Back to browse · API

CVE-2022-4830

Severity
MEDIUM
CVSS
6.1
EPSS
0.65006
Risk score
47.15
CISA KEV
No
PoC
No
Published
2023-02-13
Modified
2024-10-01
First seen
2026-08-07
Aliases
EUVD-2022-52107, GHSA-WCMJ-F23C-WRX2
Products
Unknown:Paid Memberships Pro 0 <2.9.9
Sources
euvd EUVD-2022-52107

Description

The Paid Memberships Pro WordPress plugin before 2.9.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

References