ZeroHour

CVE-2022-0201

PoC
CVSS 3.1
6.1 medium
EPSS
3%p88
Published
()
Modified
Description

The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue

Vendors
permalink manager lite projectpermalink manager project
Products
permalink manager lite, permalink manager
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.