CVE-2022-2219: Unyson < 2.7.27 - Reflected Cross-Site Scripting
Published Jul 25, 2022
·Updated
The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
Affected Software
1 affected component
Brizy Unyson Wordpress<2.7.27
Event History
Jul 25, 2022
CVE Published
via MITRE·12:47 PM
Data Sourced
via MITRE·12:47 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-2219.
2
What is the severity of CVE-2022-2219?
The severity of CVE-2022-2219 is high with a CVSS score of 7.2.
3
Which software is affected by CVE-2022-2219?
The Unyson WordPress plugin before 2.7.27 is affected by CVE-2022-2219.
4
What is the impact of CVE-2022-2219?
CVE-2022-2219 can lead to a Reflected Cross-Site Scripting vulnerability.
5
Is there a fix for CVE-2022-2219?
Yes, updating the Unyson WordPress plugin to version 2.7.27 or later will fix CVE-2022-2219.