Логотип exploitDog
bind:CVE-2022-1772
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-1772

Количество 2

Количество 2

nvd логотип

CVE-2022-1772

больше 3 лет назад

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-46qc-38mx-3p32

больше 3 лет назад

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

CVSS3: 4.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-1772

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

CVSS3: 4.8
3%
Низкий
больше 3 лет назад
github логотип
GHSA-46qc-38mx-3p32

The Google Places Reviews WordPress plugin before 2.0.0 does not properly escape its Google API key setting, which is reflected on the site's administration panel. A malicious administrator could abuse this bug, in a multisite WordPress configuration, to trick super-administrators into viewing the booby-trapped payload and taking over their account.

CVSS3: 4.8
3%
Низкий
больше 3 лет назад

Уязвимостей на страницу