CVE-2022-0176: PowerPack Lite for Beaver Builder < 1.2.9.3 - Reflected Cross-Site Scripting
Published Feb 14, 2022
·Updated
The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Affected Software
2 affected components
Wpbeaveraddons Powerpack Lite For Beaver Builder Wordpress<1.2.9.3
IdeaBox Powerpack For Beaver Builder Wordpress<1.2.9.3
Remediation
Patch Available
Event History
Feb 14, 2022
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of the PowerPack Lite for Beaver Builder WordPress plugin vulnerability?
The vulnerability ID of the PowerPack Lite for Beaver Builder WordPress plugin vulnerability is CVE-2022-0176.
2
What is the severity of CVE-2022-0176?
The severity of CVE-2022-0176 is medium with a severity value of 6.1.
3
What is the affected software?
The affected software is PowerPack Lite for Beaver Builder WordPress plugin before version 1.2.9.3.
4
What is the description of CVE-2022-0176?
CVE-2022-0176 is a Reflected Cross-Site Scripting vulnerability in the PowerPack Lite for Beaver Builder WordPress plugin before version 1.2.9.3.
5
How can I fix CVE-2022-0176?
To fix CVE-2022-0176, update the PowerPack Lite for Beaver Builder WordPress plugin to version 1.2.9.3 or later.