Record summary

CVE-2022-1051 has a selected CVSS score of 5.4 (medium); EIP currently links 1 repository PoC.

Description

The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus

WPQA Builder Plugin

CVE List5.2 to < 5.2affected

Proofs of concept

1

Repository PoCs

GitHubV35HR4J/CVE-2022-1051Repository PoCby V35HR4JStars: 2Not analyzed1 file

791 B

GitHub

PoC details

References

2