{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-23T10:00:11.705","vulnerabilities":[{"cve":{"id":"CVE-2022-3144","sourceIdentifier":"security@wordfence.com","published":"2022-09-23T14:15:12.900","lastModified":"2026-04-08T18:17:27.737","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"The Wordfence Security – Firewall & Malware Scan plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 7.6.0 via a setting on the options page due to insufficient escaping on the stored value. This makes it possible for authenticated users, with administrative privileges, to inject malicious web scripts into the setting that executes whenever a user accesses a page displaying the affected setting on sites running a vulnerable version."},{"lang":"es","value":"El plugin Wordfence Security - Firewall &amp; Malware Scan para WordPress es vulnerable a un ataque de tipo Cross-Site Scripting Almacenado en versiones hasta 7.6.0 incluyéndola, por medio de una configuración en la página de opciones debido a un escape insuficiente en el valor almacenado. Esto hace posible que usuarios autenticados, con privilegios administrativos, inyecten scripts web maliciosos en la configuración que es ejecutada cada vez que un usuario accede a una página que muestra la configuración afectada en los sitios que ejecutan una versión vulnerable."}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":4.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.7,"impactScore":2.7}]},"weaknesses":[{"source":"security@wordfence.com","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wordfence:wordfence_security:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"7.6.0","matchCriteriaId":"FBBE93A3-2A94-4965-BDE1-3D19B2DB8777"}]}]}],"references":[{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2780937%40wordfence&new=2780937%40wordfence&sfp_email=&sfph_mail=","source":"security@wordfence.com","tags":["Patch","Third Party Advisory"]},{"url":"https://wordpress.org/plugins/wordfence/#developers","source":"security@wordfence.com","tags":["Release Notes"]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/833eb481-4fb4-432e-8e93-3f497ccbf1eb?source=cve","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/vulnerability-advisories/#CVE-2022-3144","source":"security@wordfence.com","tags":["Third Party Advisory"]},{"url":"https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2780937%40wordfence&new=2780937%40wordfence&sfp_email=&sfph_mail=","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://wordpress.org/plugins/wordfence/#developers","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"]},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/833eb481-4fb4-432e-8e93-3f497ccbf1eb?source=cve","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.wordfence.com/vulnerability-advisories/#CVE-2022-3144","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}