nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-29444 CVE-2022-29444
MEDIUM
WordPress Breeze plugin <= 2.0.2 - Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability
Record summary
CVE-2022-29444 has a selected CVSS score of 6.5 (medium).
Description
Plugin Settings Change leading to Cross-Site Scripting (XSS) vulnerability in Cloudways Breeze plugin <= 2.0.2 on WordPress allows users with a subscriber or higher user role to execute any of the wp_ajax_* actions in the class Breeze_Configuration which includes the ability to change any of the plugin's settings including CDN setting which could be further used for XSS attack.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 2, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Breeze (WordPress plugin)Browse Cloudways / Breeze (WordPress plugin) | CVE List | <= 2.0.2 to ≤ 2.0.2 | affected |
| VulnCheck | Version data not supplied | ||
References
3patchstack.comConfirmation
https://patchstack.com/database/vulnerability/breeze/wordpress-breeze-plugin-2-0-2-plugin-settings-change-leading-to-cross-site-scripting-xss-vulnerability wordpress.orgConfirmation
https://wordpress.org/plugins/breeze