Sploitus

CVE-2022-0205

1 known exploit for CVE-2022-0205

The YOP Poll WordPress plugin before 6.3.5 does not sanitise and escape some of the settings (available to users with a role as low as author) before outputting them, leading to a Stored Cross-Site Scripting issue

Affected products
Yop Poll
Yop-poll
< 6.3.5
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.6% (46th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2022-03-07
CVE-2022-0205 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-0205

Proof-of-concept code and exploit modules indexed by Sploitus