CVE-2022-0288
Ad Inserter < 2.7.10 - Reflected Cross-Site Scripting
Record summary
CVE-2022-0288 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Ad Inserter WordPress plugin before 2.7.10, Ad Inserter Pro WordPress plugin before 2.7.10 do not sanitise and escape the html_element_selection parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jan 24, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
Ad Inserter Pro | CVE List | 2.7.10 to < 2.7.10 | affected |
Ad Inserter – Ad Manager & AdSense Ads | CVE List | 2.7.10 to < 2.7.10 | affected |
ad_inserter_proBrowse ad_inserter_pro_project / ad_inserter_pro | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Ad Inserter <2.7.10 - Cross-Site ScriptingCVSS 6.1
WordPress Ad Inserter plugin before 2.7.10 contains a cross-site scripting vulnerability. It does not sanitize and escape the html_element_selection parameter before outputting it back in the page.
Impact
Successful exploitation of this vulnerability could lead to cross-site scripting (XSS) attacks, allowing attackers to execute malicious scripts in the context of the victim's browser.
Remediation
Fixed in version 2.7.12
Source: ProjectDiscovery