nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1582 CVE-2022-1582
MEDIUM
External Links in New Window / New Tab < 1.43 - Unauthenticated Stored Cross-Site Scripting
Record summary
CVE-2022-1582 has a selected CVSS score of 6.1 (medium); EIP currently links 2 curated repository PoCs.
Description
The External Links in New Window / New Tab WordPress plugin before 1.43 does not properly escape URLs it concatenates to onclick event handlers, which makes Stored Cross-Site Scripting attacks possible.
Description source: CVE List
Exploitation context
Available material
- Curated repository PoCs
- 2
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
External Links in New Window / New Tab | CVE List | 1.43 to < 1.43 | affected |
Proofs of concept
2Curated repository PoCs
GitHubCVE-2022-1582Curated repository PoCby yubsyStars: 112Not analyzed1 file
GitHubCVE-2022-1582Curated repository PoCby 0xd3vilStars: 127Not analyzed1 file
References
2wpscan.com
https://wpscan.com/vulnerability/cbb75383-4351-4488-aaca-ddb0f6f120cd