The Dokan WordPress plugin before 3.6.4 allows vendors to inject arbitrary javascript in product reviews, which may allow them to run stored XSS attacks against other users like site administrators.
History

Mon, 02 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-01-16T15:53:36.500Z

Updated: 2025-06-02T15:10:22.999Z

Reserved: 2022-09-13T10:02:00.257Z

Link: CVE-2022-3194

cve-icon Vulnrichment

Updated: 2024-08-03T01:00:10.810Z

cve-icon NVD

Status : Modified

Published: 2024-01-16T16:15:09.883

Modified: 2025-06-02T16:15:23.703

Link: CVE-2022-3194

cve-icon Redhat

No data.