CVE-2022-4306
Panda Pods Repeater Field < 1.5.4 - Reflected XSS
Record summary
CVE-2022-4306 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.
Description
The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 27, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Panda Pods Repeater FieldDefault status: unaffected | CVE List | Before 1.5.4 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Panda Pods Repeater Field <1.5.4 - Cross-Site ScriptingCVSS 5.4
WordPress Panda Pods Repeater Field before 1.5.4 contains a cross-site scripting vulnerability. The plugin does not sanitize and escape a parameter before outputting it back in the page. This can be leveraged against a user who has at least Contributor permission. An attacker can also steal cookie-based authentication credentials and launch other attacks.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.
Remediation
Fixed in version 1.5.4.
Source: ProjectDiscovery