CVE Vulnerabilities

CVE-2022-4790

Published: Jan 23, 2023 | Modified: Apr 02, 2025
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The WP Google My Business Auto Publish WordPress plugin before 3.4 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

Affected Software

NameVendorStart VersionEnd Version
Auto_publish_for_google_my_businessAuto_publish_for_google_my_business_project*3.4 (excluding)

References