First published: Mon Feb 21 2022(Updated: )
The GiveWP WordPress plugin before 2.17.3 does not escape the json parameter before outputting it back in an attribute in the Import admin dashboard, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Givenu Givenu Give | <2.17.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-0252 is medium, with a severity value of 6.1.
The affected software for CVE-2022-0252 is the GiveWP WordPress plugin before version 2.17.3.
CVE-2022-0252 is a Reflected Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2022-0252, update the GiveWP WordPress plugin to version 2.17.3 or later.
You can find more information about CVE-2022-0252 at the following references: [Reference 1](https://plugins.trac.wordpress.org/changeset/2659032) and [Reference 2](https://wpscan.com/vulnerability/b0e551af-087b-43e7-bdb7-11d7f639028a).