Record summary

CVE-2022-0533 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Ditty (formerly Ditty News Ticker)

CVE List3.0.15 to < 3.0.15affected

Nuclei templates

1
ProjectDiscoveryMEDIUMDitty (formerly Ditty News Ticker) < 3.0.15 - Cross-Site ScriptingCVSS 6.1

The Ditty (formerly Ditty News Ticker) WordPress plugin before 3.0.15 is affected by a Reflected Cross-Site Scripting (XSS) vulnerability.

Impact

Authenticated attackers can inject malicious JavaScript via the tab parameter, potentially stealing administrator session cookies or performing administrative actions.

Remediation

upgrade to v.3.0.15

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2022xssditty-news-tickerwpwordpresswpscanwp-pluginauthenticatedmetaphorcreationsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:metaphorcreations:ditty:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/ditty-news-ticker/
FOFA: body=/wp-content/plugins/ditty-news-ticker/

Source: ProjectDiscovery

References

3