CVE-2022-0531: WPvivid Backup and Migration Plugin < 0.9.70 - Reflected Cross-Site Scripting
Published Apr 11, 2022
·Updated
The Migration, Backup, Staging WordPress plugin before 0.9.70 does not sanitise and escape the subpage parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting
Affected Software
1 affected component
WPvivid Migration\, Backup\, Staging Wordpress<0.9.70
Event History
Apr 11, 2022
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-0531.
2
What is the severity of CVE-2022-0531?
The severity of CVE-2022-0531 is medium.
3
What is the affected software of CVE-2022-0531?
The affected software of CVE-2022-0531 is the Migration, Backup, Staging WordPress plugin before version 0.9.70.
4
What is the CWE ID of CVE-2022-0531?
The CWE ID of CVE-2022-0531 is CWE-79.
5
How do I fix CVE-2022-0531?
To fix CVE-2022-0531, update the Migration, Backup, Staging WordPress plugin to version 0.9.70 or later.