CVE-2022-0189
The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_items_row_action AJAX action before outputting it back in the response, leading to a Reflected Cross-Site Scripting
- Affected products
- Wp Rss Aggregator
- Wprssaggregator Wp Rss Aggregator
- < 4.20
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2022-02-28
CVE-2022-0189 at NVD
1 known exploit for CVE-2022-0189
Proof-of-concept code and exploit modules indexed by Sploitus