CVE-2022-4479


Table of Contents Plus < 2212 - Contributor+ Stored XSS

The Table of Contents Plus WordPress plugin before 2212 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.



We have discovered 8 live websites that are affected by CVE-2022-4479.

Contact us to get more info




Affected Software

Product  Table of Contents Plus
Category Widgets
Vulnerable Versions
  • from 0 before 2212
Total Vulnerable Versions6
Vulnerable Domains8 live websites (100.00% of Table of Contents Plus install base)


Common Weakness Enumeration


CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 9, 2023
  • Updated - Jan 10, 2023

Credits

  • Lana Codes (finder)
  • WPScan (coordinator)





Countries

United States3 websites
Japan2 websites

TLDs

.com6 websites
.net2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2022-4479

Top websites that are affected by CVE-2022-4479. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.********.com ***,***
*************.com United States***,***
*****.com Japan*,***,***
**********.com Japan*,***,***
***.**************.com United States*,***,***
**.*************.com United States*,***,***
**************.net *,***,***
***.**************.net *,***,***
See full domain list