Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ad Injection Project Subscribe
Filtered by product Ad Injection
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-0661 1 Ad Injection Project 1 Ad Injection 2022-04-26 6.5 MEDIUM 7.2 HIGH
The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set.