ZeroHour

CVE-2022-0150

PoC
CVSS 3.1
6.1 medium
EPSS
2%p76
Published
()
Modified
Description

The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

Vendors
wp accessibility helper project
Products
wp accessibility helper
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.