Vulnerabilities > CVE-2022-0446 - Unspecified vulnerability in Simple Banner Project Simple Banner

047910
CVSS 4.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
simple-banner-project

Summary

The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Vulnerable Configurations

Part Description Count
Application
Simple_Banner_Project
57