CVE-2022-0381: Embed Swagger <= 1.0.0 Reflected Cross-Site Scripting
The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0381?
CVE-2022-0381 has a high severity rating due to its capability to allow XSS attacks.
How do I fix CVE-2022-0381?
To fix CVE-2022-0381, update the Embed Swagger WordPress plugin to a version above 1.0.0.
What type of attack does CVE-2022-0381 enable?
CVE-2022-0381 enables reflected cross-site scripting (XSS) attacks.
Which versions of the Embed Swagger plugin are affected by CVE-2022-0381?
CVE-2022-0381 affects all versions of the Embed Swagger plugin up to and including version 1.0.0.
What could an attacker achieve by exploiting CVE-2022-0381?
By exploiting CVE-2022-0381, an attacker could inject arbitrary web scripts, potentially compromising user data or session information.