4.3
CVSSv2

CVE-2022-0901

Published: 04/04/2022 Updated: 11/04/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The Ad Inserter Free and Pro WordPress plugins prior to 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ad inserter project ad inserter

Exploits

WordPress Ad Inserter versions prior to 2712 suffer from a cross site scripting vulnerability ...