CVE-2022-2170

MEDIUM

Microsoft Advertising Universal Event Tracking WordPress <1.0.4 - XSS

Title source: llm
STIX 2.1

Description

The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. Due to the nature of this plugin, well crafted XSS can also leak into the frontpage.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://wpscan.com/vulnerability/6eaef938-ce98-4d57-8a1d-fa9d1ae3d6ed

Scores

CVSS v3 4.8
EPSS 0.0109
EPSS Percentile 61.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
microsoft/microsoft_advertising_universal_event_tracking < 1.0.4
Published Aug 01, 2022
Tracked Since Feb 18, 2026