PoC Index

CVE-2022-3194

MEDIUM 5.4EPSS 0.5%

The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.49% chance of exploitation in the next 30 days, 40th percentile
Published
2024-01-16
Updated
2025-06-02

Proof-of-concept exploits (1)

References

Related