Bootstrap Shortcodes [bootstrap-shortcodes] <= 3.4.0 (unfixed + closed)
unknown
[en] The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 21, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'id' parameters in the 'bs_dropdown' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbi...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in the 'bs_icon' shortcode in versions up to, and including, 3.4.0. This may make it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web sc...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the 'bs_notification' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary w...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' parameter in the 'bs_well' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'href' parameters in the 'bs_tab' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in the 'bs_row' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter in the 'bs_col' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scrip...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the 'bs_tcontent' shortcode in versions up to, and including, 3.4.0. This may make it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' parameter in the 'bs_label' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scri...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size', 'type', and 'href' parameters in the 'bs_button' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inj...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
CVE-2022-4777 on NVD →
Bootstrap Shortcodes [bootstrap-shortcodes] <= 3.4.0 (unfixed + closed)
unknown
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' and 'id' parameters in the 'bs_dropdown' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbi...
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 27, 2023
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'parent' parameters in the 'bs_citem' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitr...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 26, 2023
CVE-2022-4777 on NVD →
BootStrap Shortcode <= 3.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The BootStrap Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the 'bs_collapse' shortcode in versions up to, and including, 3.4.0. This makes it possible for authenticated attackers with the 'edit posts' capability, such as contributors, to inject arbitrary web scr...
- CVSS:
- 6.4
- Affected:
- up to 3.4.0
- Fix:
- No patched version reported
- Disclosed:
- Jan 26, 2023
CVE-2022-4777 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database