Vulnerability CVE-2022-2655


Published: 2022-09-16

Description:
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://wpscan.com/vulnerability/acc9675a-56f6-411a-9594-07144c2aad1b

Copyright 2026, cxsecurity.com

 

Back to Top