Vulnerabilities > CVE-2022-29430 - Unspecified vulnerability in PNG to JPG Project PNG to JPG
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
Cross-Site Scripting (XSS) vulnerability in KubiQ's PNG to JPG plugin <= 4.0 at WordPress via Cross-Site Request Forgery (CSRF). Vulnerable parameter &jpg_quality.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- https://patchstack.com/database/vulnerability/png-to-jpg/wordpress-png-to-jpg-plugin-4-0-cross-site-request-forgery-csrf-leading-to-persistent-cross-site-scripting-xss-vulnerability
- https://patchstack.com/database/vulnerability/png-to-jpg/wordpress-png-to-jpg-plugin-4-0-cross-site-request-forgery-csrf-leading-to-persistent-cross-site-scripting-xss-vulnerability
- https://wordpress.org/plugins/png-to-jpg/#developers
- https://wordpress.org/plugins/png-to-jpg/#developers