CVE-2022-0252

The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting
References
Link Resource
https://plugins.trac.wordpress.org/changeset/2659032 Release Notes Third Party Advisory
https://wpscan.com/vulnerability/b0e551af-087b-43e7-bdb7-11d7f639028a Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:givewp:givewp:*:*:*:*:*:wordpress:*:*

Information

Published : 2022-02-21 11:15

Updated : 2022-02-28 08:56


NVD link : CVE-2022-0252

Mitre link : CVE-2022-0252

Products Affected
No products.
CWE