Invitation Based Registrations [invitation-based-registrations] < 2.3.1 (closed)
unknown
[en] The Invitation Based Registrations WordPress plugin through 2.2.84 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.1
- Disclosed:
- Aug 1, 2022
CVE-2022-2325 on NVD →
Invitation Based Registrations <= 2.2.84 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Invitation Based Registrations WordPress plugin through 2.2.84 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed (for example in multisite setup)
- CVSS:
- 5.5
- Affected:
- up to 2.2.84
- Fixed in:
- 2.3.1
- Disclosed:
- Jul 5, 2022
CVE-2022-2325 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database