CVE-2022-40694: WordPress News Announcement Scroll plugin <= 8.8.8 - Auth. Stored Cross-Site Scripting (XSS) vulnerability
Published Nov 17, 2022
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in News Announcement Scroll plugin <= 8.8.8 on WordPress.
Affected Software
1 affected component
StoreApps News Announcement Scroll Wordpress<=8.8.8
Remediation
Information
Update to 9.0.0 or higher version.
Event History
Nov 17, 2022
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-40694?
CVE-2022-40694 has a medium severity rating due to its potential to allow stored Cross-Site Scripting attacks.
2
How do I fix CVE-2022-40694?
To fix CVE-2022-40694, update the News Announcement Scroll plugin to version 8.8.9 or later.
3
Who is affected by CVE-2022-40694?
CVE-2022-40694 affects users of the News Announcement Scroll plugin version 8.8.8 and below on WordPress.
4
What type of vulnerability is CVE-2022-40694?
CVE-2022-40694 is an authenticated stored Cross-Site Scripting (XSS) vulnerability.
5
Are there any workarounds for CVE-2022-40694?
Currently, the best workaround for CVE-2022-40694 is to disable or delete the vulnerable plugin until it is updated.