Record summary

CVE-2022-3506 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 14, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListBefore 2.1.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Related Posts <2.1.3 - Stored Cross-Site ScriptingCVSS 5.4

WordPress Related Posts plugin prior to 2.1.3 contains a cross-site scripting vulnerability in the rp4wp[heading_text] parameter. User input is not properly sanitized, allowing the insertion of arbitrary code that can allow an attacker to steal cookie-based authentication credentials and launch other attacks.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the website, potentially leading to unauthorized access, data theft, or defacement.

Remediation

Update to the latest version of the WordPress Related Posts plugin (2.1.3 or higher) to mitigate the vulnerability.

WeaknessesCWE-79
Authorsarafatansari
Template tagscve2022cvewordpresswpwp-pluginrelatedpostsxssauthenticatedhuntrnever5vuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:never5:related_posts:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3