Record summary

CVE-2022-2219 has a selected CVSS score of 7.2 (high); EIP currently links 1 Nuclei template.

Description

The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Unyson

CVE List2.7.27 to < 2.7.27affected

Nuclei templates

1
ProjectDiscoveryHIGHUnyson < 2.7.27 - Cross Site ScriptingCVSS 7.2

The plugin does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

Impact

Successful exploitation of this vulnerability could lead to unauthorized access, data theft, and potential compromise of the affected website.

Remediation

Fixed in version 2.7.27

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2022authenticatedwordpresswpxssunysonwp-pluginwpscanbrizyvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:brizy:unyson:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2