CVE-2022-2655: Classified Listing Pro < 2.0.20 - Reflected Cross-Site Scripting
Published Sep 16, 2022
·Updated
The Classified Listing Pro WordPress plugin before 2.0.20 does not escape a generated URL before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
Affected Software
2 affected components
RadiusTheme Classified Listing Pro - Classified Ads \& Business Directory Wordpress<2.0.20
RadiusTheme Classified Listing Wordpress<2.0.20
Event History
Sep 16, 2022
CVE Published
via MITRE·08:40 AM
Data Sourced
via MITRE·08:40 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-2655.
2
What is the severity of CVE-2022-2655?
The severity of CVE-2022-2655 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2022-2655?
The affected software for CVE-2022-2655 is the Classified Listing Pro WordPress plugin before version 2.0.20.
4
What is the impact of CVE-2022-2655?
CVE-2022-2655 allows an attacker to execute malicious scripts in the context of an admin page, potentially leading to unauthorized actions or data theft.
5
How can CVE-2022-2655 be fixed?
To fix CVE-2022-2655, update the Classified Listing Pro WordPress plugin to version 2.0.20 or higher.