nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1051 CVE-2022-1051
MEDIUM
WPQA < 5.2 - Subscriber+ Stored Cross-Site Scripting via Profile fields
Record summary
CVE-2022-1051 has a selected CVSS score of 5.4 (medium); EIP currently links 1 repository PoC.
Description
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WPQA Builder Plugin | CVE List | 5.2 to < 5.2 | affected |
Proofs of concept
1Repository PoCs
GitHubV35HR4J/CVE-2022-1051Repository PoCby V35HR4JStars: 2Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/cb2fa587-da2f-460e-a402-225df7744765