WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Summary
| CVE | CVE-2022-2941 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-06 18:15:15 UTC |
| Updated | 2026-04-08 18:17:26 UTC |
| Description | The WP-UserOnline plugin for WordPress has multiple Stored Cross-Site Scripting vulnerabilities in versions up to, and including 2.88.0. This is due to the fact that all fields in the "Naming Conventions" section do not properly sanitize user input, nor escape it on output. This makes it possible for authenticated attackers, with administrative privileges, to inject JavaScript code into the setting that will execute whenever a user accesses the injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. |
Risk And Classification
Primary CVSS: v3.1 4.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-79 | CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 4.8 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | [email protected] | Secondary | 5.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N |
| 3.1 | CNA | DECLARED | 5.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wp-useronline Project | Wp-useronline | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Gamerz | WP-UserOnline | affected 2.88.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Vulnerability Advisories - Wordfence | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| WordPress WP-UserOnline 2.88.0 Cross Site Scripting ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | Exploit, Third Party Advisory, VDB Entry |
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | Patch |
| Fixed XSS. Props Juampa Rodriguez · lesterchan/wp-useronline@59c76b2 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch |
| WordPress WP-UserOnline 2.88.0 Cross Site Scripting ≈ Packet Storm | MITRE | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Juampa Rodríguez (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2022-08-22T00:00:00.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.