First published: Mon Jul 11 2022(Updated: )
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Averta Shortcodes and Extra Features for Phlox Theme | <2.9.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1910 is a vulnerability in the Shortcodes and extra features for Phlox WordPress plugin before version 2.9.8 that allows for Reflected Cross-Site Scripting attacks.
The Averta Shortcodes and Extra Features for Phlox Theme plugin for WordPress versions up to and excluding 2.9.8 is affected.
CVE-2022-1910 has a severity score of 6.1, which is considered medium.
To fix CVE-2022-1910, update the Shortcodes and extra features for Phlox WordPress plugin to version 2.9.8 or higher.
The CWE for CVE-2022-1910 is CWE-79, which stands for Improper Neutralization of Input During Web Page Generation.