
Cloud Vulnerability DB
A community-led vulnerabilities database
An authenticated stored Cross-Site Scripting (XSS) vulnerability was discovered in WHA's Word Search Puzzles game WordPress plugin versions 2.0.1 and below. The vulnerability was identified and disclosed in August 2022, leading to the plugin being closed on September 5, 2022 (WordPress Plugin).
The vulnerability is identified as CVE-2022-37335 and affects the Word Search Puzzles game WordPress plugin. The issue allows authenticated users with author or higher privileges to perform stored cross-site scripting attacks (Patchstack Database).
The vulnerability could allow authenticated attackers to inject malicious JavaScript code that would execute in other users' browsers when they visit the affected pages. This could potentially lead to theft of sensitive information, session hijacking, or other malicious actions performed in the context of the affected users' sessions.
Due to the security issue, the plugin was closed and removed from the WordPress plugin repository on September 5, 2022. Users are advised to uninstall the plugin and find alternative solutions for word search puzzle functionality (WordPress Plugin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."