CVE-2022-4301: Sunshine Photo Cart < 2.9.15 - Reflected XSS
The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4301?
CVE-2022-4301 is a vulnerability in the Sunshine Photo Cart WordPress plugin before version 2.9.15 that allows for Reflected Cross-Site Scripting (XSS).
How does CVE-2022-4301 affect the Sunshine Photo Cart plugin?
CVE-2022-4301 affects the Sunshine Photo Cart plugin by not properly sanitizing and escaping a parameter before displaying it on a page, which leads to a Reflected Cross-Site Scripting vulnerability.
What is the severity of CVE-2022-4301?
The severity of CVE-2022-4301 is medium with a CVSS score of 6.1.
How can I fix CVE-2022-4301?
To fix CVE-2022-4301, you should update the Sunshine Photo Cart plugin to version 2.9.15 or above, which includes the necessary sanitization and escape measures.
Is there any additional information about CVE-2022-4301?
Yes, you can find more information about CVE-2022-4301 at the following reference: [link reference](https://wpscan.com/vulnerability/a8dca528-fb70-44f3-8149-21385039179d)