CVE-2022-0148: All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)
The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is vulnerability CVE-2022-0148?
Vulnerability CVE-2022-0148 refers to a reflected XSS vulnerability in the All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before version 2.0.4.
What is the severity of vulnerability CVE-2022-0148?
The severity of vulnerability CVE-2022-0148 is medium with a CVSS score of 5.4.
What software versions are affected by vulnerability CVE-2022-0148?
Vulnerability CVE-2022-0148 affects All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin versions up to, but excluding, 2.0.4.
How can I fix vulnerability CVE-2022-0148?
To fix vulnerability CVE-2022-0148, you should update the All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin to version 2.0.4 or later.
What is the Common Weakness Enumeration (CWE) ID for vulnerability CVE-2022-0148?
The Common Weakness Enumeration (CWE) ID for vulnerability CVE-2022-0148 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').