CVE-2022-1724
Simple Membership < 4.1.1 - Reflected Cross-Site Scripting
Record summary
CVE-2022-1724 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Simple Membership | CVE List | 4.1.1 to < 4.1.1 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Simple Membership <4.1.1 - Cross-Site ScriptingCVSS 6.1
WordPress Simple Membership plugin before 4.1.1 contains a reflected cross-site scripting vulnerability. It does not properly sanitize and escape parameters before outputting them back in AJAX actions.
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.
Remediation
Update to the latest version of WordPress Simple Membership plugin (4.1.1 or higher) to mitigate the vulnerability.
Source: ProjectDiscovery