CVE-2022-3415
14.11.2022, 15:15
The Chat Bubble WordPress plugin before 2.3 does not sanitise and escape some contact parameters, which could allow unauthenticated attackers to set Stored Cross-Site Scripting payloads in them, which will trigger when an admin view the related contact message
Vendor | Product | Version |
---|---|---|
bluecoral | chat_bubble | 𝑥 < 2.3 |
𝑥
= Vulnerable software versions