CVE-2022-0648: Team Circle Image Slider With Lightbox < 1.0.16 - Reflected Cross-Site Scripting
The Team Circle Image Slider With Lightbox WordPress plugin before 1.0.16 does not sanitize and escape the orderpos parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0648?
CVE-2022-0648 is a vulnerability found in the Team Circle Image Slider With Lightbox WordPress plugin before version 1.0.16 that allows for Reflected Cross-Site Scripting.
How severe is CVE-2022-0648?
CVE-2022-0648 has a severity rating of 6.1, which is considered medium.
What is affected by CVE-2022-0648?
The Team Circle Image Slider With Lightbox WordPress plugin before version 1.0.16 is affected by CVE-2022-0648.
How do I fix CVE-2022-0648?
To fix CVE-2022-0648, you should update the Team Circle Image Slider With Lightbox WordPress plugin to version 1.0.16 or later.
What is the Common Weakness Enumeration (CWE) for CVE-2022-0648?
The Common Weakness Enumeration (CWE) for CVE-2022-0648 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').