← back
CVE-2022-1764CWE-352

WP-chgFontSize <= 1.8 - Arbitrary Settings Update via CSRF to Stored XSS

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
The WP-chgFontSize WordPress plugin through 1.8 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping
Affected products
Unknown · WP-chgFontSize