Vulnerability CVE-2022-29442


Published: 2022-06-15

Description:
Authenticated (subscriber or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Messages For WordPress <= 2.1.10 at WordPress.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://wordpress.org/plugins/private-messages-for-wordpress/
https://patchstack.com/database/vulnerability/private-messages-for-wordpress/wordpress-private-messages-for-wordpress-plugin-2-1-10-authenticated-stored-cross-site-scripting-xss-vulnerability

Copyright 2026, cxsecurity.com

 

Back to Top