CVE-2022-1724: Simple Membership < 4.1.1 - Reflected Cross-Site Scripting
Published Jun 13, 2022
·Updated
The Simple Membership WordPress plugin before 4.1.1 does not properly sanitise and escape parameters before outputting them back in AJAX actions, leading to Reflected Cross-Site Scripting
Affected Software
1 affected component
Simple-membership-plugin Simple Membership Wordpress<4.1.1
Event History
Jun 13, 2022
CVE Published
via MITRE·12:42 PM
Data Sourced
via MITRE·12:42 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-1724?
CVE-2022-1724 has a medium severity rating due to the potential for reflected cross-site scripting attacks.
2
How do I fix CVE-2022-1724?
To fix CVE-2022-1724, update the Simple Membership WordPress plugin to version 4.1.1 or later.
3
What are the impacts of CVE-2022-1724?
The impacts of CVE-2022-1724 include the possibility of attackers executing arbitrary scripts in a user's browser.
4
Which versions of the Simple Membership plugin are affected by CVE-2022-1724?
CVE-2022-1724 affects all versions of the Simple Membership plugin prior to 4.1.1.
5
Is CVE-2022-1724 a critical vulnerability?
CVE-2022-1724 is not considered a critical vulnerability, but it poses significant risks if exploited.