Sploitus

CVE-2022-4765

1 known exploit for CVE-2022-4765

The Portfolio for Elementor WordPress plugin before 2.3.1 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.

Affected products
Portfolio For Elementor
Pwrplugins Portfolio For Elementor
< 2.3.1
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.5% (43th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2023-01-30
CVE-2022-4765 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-4765

Proof-of-concept code and exploit modules indexed by Sploitus