CVE-2022-0176
The PowerPack Lite for Beaver Builder WordPress plugin before 1.2.9.3 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
- Affected products
- Powerpack Lite For Beaver Builder
- Ideabox Powerpack For Beaver Builder
- < 1.2.9.3
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 0.9% (56th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2022-02-14
CVE-2022-0176 at NVD
1 known exploit for CVE-2022-0176
Proof-of-concept code and exploit modules indexed by Sploitus