The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:53:36.500Z

Updated: 2024-08-03T01:00:10.810Z

Reserved: 2022-09-13T10:02:00.257Z

Link: CVE-2022-3194

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-16T16:15:09.883

Modified: 2024-01-24T15:55:36.690

Link: CVE-2022-3194

cve-icon Redhat

No data.