S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-3934 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in FlatPM plugin for WordPress affects v. before 3.0.13.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-3934
5.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

The FlatPM WordPress plugin before 3.0.13 does not sanitise and escape some parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
FlatPM
AFFECTED< 3.0.13SAFE ✓≥ 3.0.13
Updated Aug 22, 2026View on NVD →
Detail

FlatPM is a WordPress plugin designed to streamline project management for teams working on a website. This tool helps users manage tasks, track progress, and collaborate with other team members in real-time. FlatPM is an excellent choice for businesses that require efficient project management and improved workflow.

However, the use of FlatPM WordPress plugin before version 3.0.13 creates a significant vulnerability in the system, which can compromise the security of high privilege users like admin. This vulnerability is identified as Reflected Cross-Site Scripting (XSS), which means that an attacker can inject a malicious script into a web page. When unsuspecting users visit that page, the script executes, allowing the attacker to gain access to sensitive user information like login credentials, session cookies, and other sensitive data.

Exploiting this vulnerability allows attackers to gain unauthorized access to the system. They could be anyone, ranging from hackers to other individuals with malicious intent. Attackers who exploit this vulnerability can initiate attacks that could harm businesses by compromising their critical information, damaging their reputation, and violating data protection regulations.

Thanks to the pro features of the s4e.io platform, businesses can keep their digital assets secure and easily and quickly learn about vulnerabilities in their systems. With advanced features like continuous vulnerability scanning and monitoring, businesses can find vulnerabilities in their assets before attackers do. This way, they can take proactive steps to keep their systems secure and maintain their reputation.

 

REFERENCES

Solution Advice

Businesses can defend themselves against this vulnerability by taking the following precautions:

  • Regularly updating the plugin with the latest security patch to close the identified vulnerability.
  • Implementing a web application firewall (WAF) that filters and blocks malicious traffic.
  • Conducting perimeter security assessments to identify and respond to threats proactively.
  • Encouraging users to be cautious of suspicious emails, which could be phishing attempts by attackers.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.