{"id":"GHSA-qrqm-574x-q7f2","summary":"Awesome Support vulnerable to persistent cross-site scripting","details":"Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin \u003c= 6.0.7 at WordPress.","aliases":["CVE-2022-38073"],"modified":"2023-11-08T04:10:10.396723Z","published":"2022-09-22T00:00:22Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-09-29T19:06:17Z","nvd_published_at":"2022-09-21T20:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-38073"},{"type":"WEB","url":"https://github.com/Awesome-Support/Awesome-Support/commit/85f460be88b81fbdd9a990f474a1252297902faf"},{"type":"WEB","url":"https://github.com/Awesome-Support/Awesome-Support/commit/b2e831d7f831a3869cfd83eb79a398a5b5c0ec63"},{"type":"PACKAGE","url":"https://github.com/Awesome-Support/Awesome-Support"},{"type":"WEB","url":"https://patchstack.com/database/vulnerability/awesome-support/wordpress-awesome-support-plugin-6-0-7-multiple-authenticated-stored-cross-site-scripting-xss-vulnerabilities"},{"type":"WEB","url":"https://wordpress.org/plugins/awesome-support/#developers"}],"affected":[{"package":{"name":"awesome-support/awesome-support","ecosystem":"Packagist","purl":"pkg:composer/awesome-support/awesome-support"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.8"}]}],"versions":["3.0.0","3.0.0-beta-1","3.0.0-beta-2","3.0.1","3.1.0","3.1.1","3.1.10","3.1.11","3.1.12","3.1.2","3.1.3","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.8","3.2.9","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.3.4_RC01","3.3.4_RC02","3.3.4_RC03","3.3.4_RC05","3.4.0_RC01","3.6.0_RC01","3.6.0_RC02","3.6.0_RC04","3.6.0_RC05","4.0.0","4.0.0_RC01","4.0.0_RC02","4.0.0_RC03","4.0.0_RC04","4.0.0_RC05","4.0.0_RC06","4.0.0_RC07","4.0.0_RC08","4.0.0_RC09","4.0.0_RC10","4.0.0_RC11","4.0.2","4.0.3","4.0.4","4.0.5","4.0.5_RC01","4.0.5_RC02","4.0.5_RC03","4.0.5_RC04","4.0.6","4.1.0","4.2.0","4.2.1","4.3.0","4.3.1","4.3.2","4.3.4","4.3.5","4.4.0_RC01","4.4.0_RC02","4.4.0_RC03","4.4.0_RC04","4.4.0_RC05","4.4.0_RC06","4.4.0_RC07","4.4.0_RC08","4.4.0_RC09","4.4.0_RC10","4.4.0_RC11","4.4.0_RC12","5.0.0","5.1.0","5.1.1","5.2.0_RC11","5.2.0_RC13","5.2.0_RC14","5.2.0_RC16","5.2.0_RC17","5.2.0_RC18","5.2.0_RC19","5.2.0_RC20","5.2.0_RC21","5.2_RC10","5.5.0","5.5.1","5.5.2","5.6.0","5.7.0","5.7.1","5.8.0","6.0.0","6.0.1","6.0.5","6.0.6","6.0.7"],"database_specific":{"last_known_affected_version_range":"\u003c= 6.0.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-qrqm-574x-q7f2/GHSA-qrqm-574x-q7f2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}