CVE-2022-45358: WordPress Activello Theme <= 1.4.4 is vulnerable to Cross Site Scripting (XSS)
Published Apr 13, 2023
·Updated
Auth. (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Silkalns Activello theme <= 1.4.4 versions.
Affected Software
1 affected component
Colorlib Activello Wordpress<=1.4.4
Event History
Apr 13, 2023
CVE Published
via MITRE·11:36 AM
Data Sourced
via MITRE·11:36 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-45358?
CVE-2022-45358 is classified as a moderate severity reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2022-45358?
To fix CVE-2022-45358, update the Silkalns Activello theme to version 1.4.5 or later.
3
What are the consequences of CVE-2022-45358?
Exploiting CVE-2022-45358 can allow an attacker to execute arbitrary JavaScript in the user's browser.
4
Who is affected by CVE-2022-45358?
Users of the Silkalns Activello theme version 1.4.4 and below are affected by CVE-2022-45358.
5
Is CVE-2022-45358 easy to exploit?
Yes, CVE-2022-45358 can be relatively easy to exploit if proper input validation is not in place.