CVE-2022-0200: Themify Portfolio Post < 1.1.7 - Reflected Cross-Site Scripting
Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the numofpages parameter before outputting it back the response of the themifycreatepopuppagepagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0200?
CVE-2022-0200 is classified with a severity that may allow authenticated users to execute reflected cross-site scripting attacks.
How do I fix CVE-2022-0200?
To fix CVE-2022-0200, upgrade the Themify Portfolio Post plugin to version 1.1.7 or later.
Who is affected by CVE-2022-0200?
CVE-2022-0200 affects any user of the Themify Portfolio Post WordPress plugin prior to version 1.1.7.
What kind of vulnerability is CVE-2022-0200?
CVE-2022-0200 is a reflected cross-site scripting vulnerability stemming from improper sanitization and escaping of user input.
Can unauthenticated users exploit CVE-2022-0200?
No, CVE-2022-0200 can only be exploited by authenticated users due to its access conditions.