6.1
CVSSv3

CVE-2022-1218

CVSSv4: NA | CVSSv3: 6.1 | CVSSv2: 4.3 | VMScore: 710 | EPSS: 0.00084 | KEV: Not Included
Published: 23/05/2022 Updated: 21/11/2024

Vulnerability Summary

The Domain Replace WordPress plugin up to and including 1.3.8 does not sanitise and escape a parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

duogeek domain replace