CVE-2022-0201

The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:permalink_manager_lite_project:permalink_manager_lite:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:permalink_manager_project:permalink_manager:*:*:*:*:pro:wordpress:*:*

History

19 Feb 2022, 04:21

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.1
CPE cpe:2.3:a:permalink_manager_project:permalink_manager:*:*:*:*:pro:wordpress:*:*
cpe:2.3:a:permalink_manager_lite_project:permalink_manager_lite:*:*:*:*:*:wordpress:*:*
References (MISC) https://wpscan.com/vulnerability/f274b0d8-74bf-43de-9051-29ce36d78ad4 - (MISC) https://wpscan.com/vulnerability/f274b0d8-74bf-43de-9051-29ce36d78ad4 - Exploit, Third Party Advisory
References (CONFIRM) https://plugins.trac.wordpress.org/changeset/2656512 - (CONFIRM) https://plugins.trac.wordpress.org/changeset/2656512 - Patch, Third Party Advisory

14 Feb 2022, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-14 12:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-0201

Mitre link : CVE-2022-0201

CVE.ORG link : CVE-2022-0201


JSON object : View

Products Affected

permalink_manager_lite_project

  • permalink_manager_lite

permalink_manager_project

  • permalink_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')