vulnerability

WordPress Plugin: simple-post-notes: CVE-2022-2186: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Severity
3
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
Jun 22, 2022
Added
May 15, 2025
Modified
May 15, 2025

Description

The Simple Post Notes plugin for WordPress is vulnerable to subscriber+ Stored Cross-Site Scripting via the 'spnote' parameter saved via the save_bulkedit_note() function which gets called through the wp_ajax_spnote_save_bulk_edit AJAX action. This affects versions up to 1.7.6, and version 1.7.6 is still vulnerable to unauthorized post note changes by subscriber level users due to a missing capability check on the spnote_save_bulk_edit action.

Solution

simple-post-notes-plugin-cve-2022-2186
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.