CVE-2022-1910: Shortcodes and extra features for Phlox theme < 2.9.8 - Reflected Cross-Site-Scripting
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-1910?
CVE-2022-1910 is a vulnerability in the Shortcodes and extra features for Phlox WordPress plugin before version 2.9.8 that allows for Reflected Cross-Site Scripting attacks.
What software is affected by CVE-2022-1910?
The Averta Shortcodes and Extra Features for Phlox Theme plugin for WordPress versions up to and excluding 2.9.8 is affected.
How severe is CVE-2022-1910?
CVE-2022-1910 has a severity score of 6.1, which is considered medium.
How can I fix CVE-2022-1910?
To fix CVE-2022-1910, update the Shortcodes and extra features for Phlox WordPress plugin to version 2.9.8 or higher.
What is the Common Weakness Enumeration (CWE) for CVE-2022-1910?
The CWE for CVE-2022-1910 is CWE-79, which stands for Improper Neutralization of Input During Web Page Generation.