Record summary

CVE-2022-1724 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Simple Membership

CVE List4.1.1 to < 4.1.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Simple Membership <4.1.1 - Cross-Site ScriptingCVSS 6.1

WordPress Simple Membership plugin before 4.1.1 contains a reflected cross-site scripting vulnerability. It does not properly sanitize and escape parameters before outputting them back in AJAX actions.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into web pages viewed by users, leading to potential data theft, session hijacking, or defacement of the affected website.

Remediation

Update to the latest version of WordPress Simple Membership plugin (4.1.1 or higher) to mitigate the vulnerability.

WeaknessesCWE-79
AuthorsAkincibor
Template tagscvecve2022xsswpwordpresswpscanwp-pluginsimple-membership-pluginvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:simple-membership-plugin:simple_membership:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2