← Back

CVE-2022-33994

nvd nist
Published: Jul 30, 2022Modified: Jun 17, 2026

JSON object

Loading...
3.0
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
Exploitability: 1.3 / Impact: 1.4
Source: NVD

Description

The Gutenberg plugin through 13.7.3 for WordPress allows stored XSS by the Contributor role via an SVG document to the "Insert from URL" feature. NOTE: the XSS payload does not execute in the context of the WordPress instance's domain; however, analogous attempts by low-privileged users to reference SVG documents are blocked by some similar products, and this behavioral difference might have security relevance to some WordPress site administrators.

Affected (1)

Gutenberg
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 13.7.3

References (4)

Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.