CVE-2022-2654: Classima < 2.1.11 - Reflected Cross-Site Scripting
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2654?
CVE-2022-2654 is a vulnerability in the Classima WordPress theme and some of its required plugins that allows for parameter injection.
How does CVE-2022-2654 impact websites using the Classima WordPress theme?
CVE-2022-2654 can allow an attacker to inject and execute malicious code on websites using the Classima WordPress theme.
What is the severity of CVE-2022-2654?
CVE-2022-2654 has a severity rating of 6.1, which is considered medium.
Which versions of the Classima WordPress theme and its required plugins are affected by CVE-2022-2654?
The Classima WordPress theme versions before 2.1.11, Classified Listing versions before 2.2.14, Classified Listing Pro versions before 2.0.20, Classified Listing Store & Membership versions before 1.4.20, and Classima Core versions before 1.10 are affected by CVE-2022-2654.
How can I fix CVE-2022-2654?
To fix CVE-2022-2654, it is recommended to update your Classima WordPress theme and its required plugins to the latest versions.