CVE-2022-28222: CleanTalk AntiSpam <= 5.173 Reflected XSS
The CleanTalk AntiSpam plugin <= 5.173 for WordPress is vulnerable to Reflected Cross-Site Scripting (XSS) via the $REQUEST['page'] parameter in/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28222?
CVE-2022-28222 is a vulnerability in the CleanTalk AntiSpam plugin <= 5.173 for WordPress that allows for Reflected Cross-Site Scripting (XSS) attacks.
How severe is CVE-2022-28222?
CVE-2022-28222 has a severity rating of 6.1, which is considered medium.
Which software versions are affected by CVE-2022-28222?
The CleanTalk AntiSpam plugin versions up to and including 5.173 for WordPress are affected by CVE-2022-28222.
How can CVE-2022-28222 be exploited?
CVE-2022-28222 can be exploited through the $_REQUEST['page'] parameter in `/lib/Cleantalk/ApbctWP/FindSpam/ListTable/Users.php`.
Is there a fix available for CVE-2022-28222?
Yes, it is recommended to update to the latest version of the CleanTalk AntiSpam plugin to mitigate the vulnerability.