Record summary

CVE-2022-0429 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs and 1 Nuclei template.

Description

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 14, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Curated repository PoCs
2
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

WP Cerber Security, Anti-spam & Malware Scan

CVE List8.9.6 to < 8.9.6affected

wp_cerber_security\,_anti-spam_\&_malware_scan

Browse cerber / wp_cerber_security\,_anti-spam_\&_malware_scan
VulnCheckVersion data not supplied

Proofs of concept

2

Curated repository PoCs

GitHubCVE-2022-0429Curated repository PoCby yubsyStars: 112Not analyzed1 file

Python · 714 B

GitHub

PoC details
GitHubCVE-2022-0429Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file

Python · 714 B

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Cross-Site ScriptingCVSS 6.1

The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.

Impact

Unauthenticated attackers can inject stored XSS payloads via unsanitized URL parameters, which execute when authenticated administrators view the Activity tab, potentially stealing session cookies or performing administrative actions.

Remediation

Upgrade to WP Cerber Security version 8.9.6 or later.

WeaknessesCWE-79
Authorss4e-io
Template tagscvecve2022wpwp-pluginwpscanwordpressxsswp-cerberauthenticatedvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:cerber:wp_cerber_security\,_anti-spam_\&_malware_scan:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2