Vulnerability CVE-2022-4782


Published: 2023-08-16

Description:
The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://wpscan.com/vulnerability/d3a0468a-8405-4b6c-800f-abd5ce5387b5

Copyright 2026, cxsecurity.com

 

Back to Top