CVE-2022-2167: Newspaper < 12 - Reflected Cross-Site Scripting
Published Oct 31, 2022
·Updated
The Newspaper WordPress theme before 12 does not sanitise a parameter before outputting it back in an HTML attribute via an AJAX action, leading to a Reflected Cross-Site Scripting
Affected Software
1 affected component
tagDiv Newspaper Wordpress<12
Event History
Oct 31, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-2167?
The severity of CVE-2022-2167 is medium with a CVSS score of 6.1.
2
What is the vulnerability type of CVE-2022-2167?
CVE-2022-2167 is a Reflected Cross-Site Scripting (XSS) vulnerability.
3
How does CVE-2022-2167 affect the Newspaper WordPress theme?
CVE-2022-2167 affects the Newspaper WordPress theme version up to exclusive version 12.
4
What is the Common Weakness Enumeration (CWE) ID of CVE-2022-2167?
The Common Weakness Enumeration (CWE) ID for CVE-2022-2167 is CWE-79.
5
Is there a fix available for CVE-2022-2167?
To fix CVE-2022-2167, it is recommended to update the Newspaper WordPress theme to version 12 or higher.