Stored XSS Vulnerability in 3com Asesor De Cookies Plugin Affects WordPress Users

Stored XSS Vulnerability in 3com Asesor De Cookies Plugin Affects WordPress Users

First seen 24 Aug 2026, 07:46 UTC Nvd.Nistpatchstack.comcve.org 80% similarity 33.9

Article Content

Browse articles
ThreatCluster

A stored cross-site scripting (XSS) vulnerability has been identified in the 3com Asesor De Cookies plugin for WordPress, specifically in versions 3.4.3 and earlier. This vulnerability, cataloged as CVE-2022-40697, requires a privileged user to exploit it, typically by clicking a malicious link or submitting a crafted form. The CVSS score indicates a low severity impact, suggesting that while the vulnerability exists, it is unlikely to be widely exploited. Users are advised to update the plugin to mitigate the risk. The vulnerability was published on January 19, 2023, and has been confirmed by multiple sources. Current status indicates that immediate action is recommended for affected users.

Key Points: • CVE-2022-40697 is a stored XSS vulnerability in the 3com Asesor De Cookies plugin. • The vulnerability affects versions 3.4.3 and earlier of the plugin used in WordPress. • Users are advised to update the plugin to prevent potential exploitation.

ThreatCluster AI How this analysis works

Timeline

2023-01-19
CVE-2022-40697 published
The stored XSS vulnerability in the 3com Asesor De Cookies plugin was officially published.
Nvd.Nist
2026-08-24
Vulnerability reported
Patchstack reported the stored XSS vulnerability in the 3com Asesor De Cookies plugin, urging users to update.
patchstack.com

Community

Browse all →

Tracked Entities in This Story