CVE-2022-1604: MailerLite < 1.5.4 - Reflected Cross-Site Scripting
Published Jun 13, 2022
·Updated
The MailerLite WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Affected Software
1 affected component
MailerLite Mailerlite Signup Forms Wordpress<1.5.4
Event History
Jun 13, 2022
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1604?
CVE-2022-1604 has a medium severity rating due to its potential for reflected cross-site scripting (XSS) attacks.
2
How do I fix CVE-2022-1604?
To fix CVE-2022-1604, update the MailerLite WordPress plugin to version 1.5.4 or later.
3
Which versions of the MailerLite plugin are affected by CVE-2022-1604?
The affected versions of the MailerLite plugin are all versions before 1.5.4.
4
What kind of attack can CVE-2022-1604 facilitate?
CVE-2022-1604 can facilitate reflected cross-site scripting (XSS) attacks that can compromise user information.
5
Is it safe to use the MailerLite plugin versions below 1.5.4 due to CVE-2022-1604?
No, it is not safe to use MailerLite plugin versions below 1.5.4 as they are vulnerable to XSS attacks.