Vulnerability CVE-2022-4307


Published: 2023-01-23

Description:
The ?????? ?????? ?????? WordPress plugin before 2.9.3 does not sanitise and escape some parameters, allowing unauthenticated attackers to send a request with XSS payloads, which will be triggered when a high privilege users such as admin visits a page from the plugin.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://wpscan.com/vulnerability/4000ba69-d73f-4c5b-a299-82898304cebb

Copyright 2026, cxsecurity.com

 

Back to Top