CVE-2022-0150
WP Accessibility Helper (WAH) < 0.6.0.7 - Reflected Cross-Site Scripting (XSS)
Record summary
CVE-2022-0150 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP Accessibility Helper (WAH) | CVE List | 0.6.0.7 to < 0.6.0.7 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Accessibility Helper <0.6.0.7 - Cross-Site ScriptingCVSS 6.1
WordPress Accessibility Helper plugin before 0.6.0.7 contains a cross-site scripting vulnerability. It does not sanitize and escape the wahi parameter before outputting back its base64 decode value in the page.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access, data theft, or defacement of the affected WordPress website.
Remediation
Update to WordPress Accessibility Helper version 0.6.0.7 or later to mitigate this vulnerability.
Source: ProjectDiscovery