CVE-2022-0201: Permalink Manager < 2.2.15 - Reflected Cross-Site Scripting
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0201?
CVE-2022-0201 has a medium severity rating due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2022-0201?
To fix CVE-2022-0201, update the Permalink Manager Lite and Permalink Manager Pro plugins to version 2.2.15 or above.
What type of vulnerability is CVE-2022-0201?
CVE-2022-0201 is a Reflected Cross-Site Scripting (XSS) vulnerability.
Which versions of the plugin are affected by CVE-2022-0201?
Versions of Permalink Manager Lite and Permalink Manager Pro prior to 2.2.15 are affected by CVE-2022-0201.
Is user input at risk from CVE-2022-0201?
Yes, user input is at risk because the vulnerability involves unsanitized query parameters in the debug page.