Record summary

CVE-2022-4306 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 27, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Panda Pods Repeater Field

Default status: unaffected

CVE ListBefore 1.5.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Panda Pods Repeater Field <1.5.4 - Cross-Site ScriptingCVSS 5.4

WordPress Panda Pods Repeater Field before 1.5.4 contains a cross-site scripting vulnerability. The plugin does not sanitize and escape a parameter before outputting it back in the page. This can be leveraged against a user who has at least Contributor permission. An attacker can also steal cookie-based authentication credentials and launch other attacks.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to potential data theft or unauthorized actions.

Remediation

Fixed in version 1.5.4.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscvecve2022xsspandapodsrepeaterwordpresswp-pluginwpscanauthenticatedpanda_pods_repeater_field_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:panda_pods_repeater_field_project:panda_pods_repeater_field:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2