Record summary

CVE-2022-0422 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

White Label CMS

CVE List2.2.9 to < 2.2.9affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress White Label CMS <2.2.9 - Cross-Site ScriptingCVSS 6.1

WordPress White Label CMS plugin before 2.2.9 contains a reflected cross-site scripting vulnerability. It does not sanitize and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Update to WordPress White Label CMS plugin version 2.2.9 or later to mitigate this vulnerability.

WeaknessesCWE-79
Authorsrandom-robbie
Template tagscve2022cvewordpressxsswp-pluginwpscanvideousermanualsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:videousermanuals:white_label_cms:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3