CVE-2022-4369
The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high-privilege users such as admin.
- Affected products
- Wp-Lister Lite For Amazon
- Wplite Wp-lister Lite For Amazon
- < 2.4.4
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 0.5% (40th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2023-01-02
CVE-2022-4369 at NVD
1 known exploit for CVE-2022-4369
Proof-of-concept code and exploit modules indexed by Sploitus