Record summary

CVE-2022-0150 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

WP Accessibility Helper (WAH)

CVE List0.6.0.7 to < 0.6.0.7affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Accessibility Helper <0.6.0.7 - Cross-Site ScriptingCVSS 6.1

WordPress Accessibility Helper plugin before 0.6.0.7 contains a cross-site scripting vulnerability. It does not sanitize and escape the wahi parameter before outputting back its base64 decode value in the page.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access, data theft, or defacement of the affected WordPress website.

Remediation

Update to WordPress Accessibility Helper version 0.6.0.7 or later to mitigate this vulnerability.

WeaknessesCWE-79
AuthorsdhiyaneshDK
Template tagscvecve2022wordpresswp-pluginwpwpscanxsswp_accessibility_helper_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wp_accessibility_helper_project:wp_accessibility_helper:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3