The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
References
Link | Resource |
---|---|
https://plugins.trac.wordpress.org/changeset/2656512 | Patch Third Party Advisory |
https://wpscan.com/vulnerability/f274b0d8-74bf-43de-9051-29ce36d78ad4 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-02-14 04:15
Updated : 2022-02-18 20:21
NVD link : CVE-2022-0201
Mitre link : CVE-2022-0201
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
permalink_manager_project
- permalink_manager
permalink_manager_lite_project
- permalink_manager_lite