Wordfence Security – Firewall & Malware Scan <= 7.6.0 - Authenticated (Admin+) Stored Cross-Site Scripting
Summary
| CVE | CVE-2022-3144 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-23 14:15:12 UTC |
| Updated | 2026-04-08 18:17:27 UTC |
| Description | The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version. |
Risk And Classification
Primary CVSS: v3.1 4.8 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Problem Types: CWE-79 | CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 4.8 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
| 3.1 | [email protected] | Secondary | 4.4 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
| 3.1 | CNA | DECLARED | 4.4 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
HighUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wordfence | Wordfence Security | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Mmaunder | Wordfence Security Firewall Malware Scan And Login Security | affected 7.6.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | plugins.trac.wordpress.org | Patch, Third Party Advisory |
| Wordfence Security – Firewall & Malware Scan – WordPress plugin | WordPress.org | af854a3a-2127-422b-91ae-364da2661108 | wordpress.org | Release Notes |
| Wordfence Security – Firewall & Malware Scan <= 7.6.0 - Authenticated (Admin+) Stored Cross-Site Scripting | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | |
| Vulnerability Advisories - Wordfence | af854a3a-2127-422b-91ae-364da2661108 | www.wordfence.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Ori Gabriel (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2022-09-05T00:00:00.000Z | Vendor Notified |
| CNA | 2022-09-06T00:00:00.000Z | Disclosed |
Legacy QID Mappings
- 150577 WordPress Wordfence Security - Firewall and Malware Scan Plugin: Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2022-3144)