Vulnerability CVE-2022-0899


Published: 2022-07-25

Description:
The Header Footer Code Manager WordPress plugin before 1.1.24 does not escape generated URLs before outputting them back in attributes in an admin page, leading to a Reflected Cross-Site Scripting.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://wpscan.com/vulnerability/1772417a-1abb-4d97-9694-1254840defd1

Copyright 2026, cxsecurity.com

 

Back to Top