CVE-2022-2391

The Inspiro PRO WordPress plugin does not sanitize the portfolio slider description, allowing users with privileges as low as Contributor to inject JavaScript into the description.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:wpzoom:inspiro_pro:*:*:*:*:*:wordpress:*:*

Information

Published : 2022-08-08 07:15

Updated : 2022-08-12 07:06


NVD link : CVE-2022-2391

Mitre link : CVE-2022-2391


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

wpzoom

  • inspiro_pro