S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 5, 2024

CVE-2022-4295 Scanner

CVE-2022-4295 scanner - Cross-Site Scripting vulnerability in Show all comments WordPress plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.4k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-4295
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The Show All Comments WordPress plugin before 7.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Show All Comments
AFFECTED< 7.0.1SAFE ✓≥ 7.0.1
Updated Aug 22, 2026View on NVD →
Detail

The Show all comments plugin for WordPress is designed to allow website administrators to display all comments on their site in a single page. It's particularly useful for sites that receive a high volume of comments, as it simplifies management and moderation for site administrators. This plugin is widely used across various WordPress websites, including blogs, news sites, and e-commerce platforms, to enhance user engagement and interaction. Developed by AppJetty, it aims to provide a more streamlined experience for both site visitors and administrators by aggregating comments in an easily accessible format.

A Reflected Cross-Site Scripting (XSS) vulnerability exists in versions of the Show all comments WordPress plugin prior to 7.0.1. This issue arises due to insufficient sanitization and escaping of user-supplied input before it is output back into the page. As a result, attackers can inject arbitrary script code into the web page viewed by other users, including administrators. This vulnerability can be exploited to execute malicious scripts in the context of the victim's browser, potentially leading to unauthorized actions and data access.

The vulnerability specifically exists within the `sac_post_type_call` AJAX action, where the `post_type` parameter is not properly sanitized before being echoed back to the user. By crafting a malicious URL that includes script tags within the `post_type` parameter, an attacker can trigger the execution of arbitrary JavaScript code in the context of the user's browser session. This particularly affects logged-in users with high privileges, such as site administrators, making it possible for attackers to perform a wide range of malicious activities.

Successful exploitation of this XSS vulnerability can lead to several security issues, including session hijacking, where attackers gain control over victims' sessions; website defacement, where the appearance of the site is altered; and theft of sensitive information. For administrators, this could mean unauthorized access to administrative functions, modification of site content, and exposure of confidential data.

By leveraging the security scanning services provided by S4E, users can identify and mitigate vulnerabilities like the XSS flaw found in the Show all comments WordPress plugin. Our platform offers comprehensive scanning solutions that detect potential security issues and provide actionable recommendations for remediation. Members benefit from ongoing security monitoring, ensuring that their websites remain protected against the latest threats and vulnerabilities.

 

References

Solution Advice
  1. Immediately update to version 7.0.1 of the Show all comments plugin, which contains the necessary fixes for this vulnerability.
  2. Ensure that all WordPress plugins and themes are kept up to date to prevent similar vulnerabilities.
  3. Utilize security plugins that provide additional protections against XSS and other web application vulnerabilities.
  4. Consider implementing a web application firewall (WAF) that can detect and block XSS attacks and other malicious inputs.
  5. Regularly review and audit website content and code for security issues, applying best practices for secure web development.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-4295 scanner - Cross-Site Scripting vulnerability in Show all comments WordPress plugin | S4E