CVE Vulnerabilities

CVE-2022-4394

Published: Jan 09, 2023 | Modified: Apr 09, 2025
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The iPages Flipbook For WordPress plugin through 1.4.6 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected Software

NameVendorStart VersionEnd Version
Ipages_flipbookIpages_flipbook_project*1.4.7 (excluding)

References