First published: Mon Apr 11 2022(Updated: )
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the sub_page parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPvivid Migration, Backup, Staging | <0.9.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2022-0531.
The severity of CVE-2022-0531 is medium.
The affected software of CVE-2022-0531 is the Migration, Backup, Staging WordPress plugin before version 0.9.70.
The CWE ID of CVE-2022-0531 is CWE-79.
To fix CVE-2022-0531, update the Migration, Backup, Staging WordPress plugin to version 0.9.70 or later.