CVE-2022-1051 Information

Description

The WPQA Builder Plugin WordPress plugin before 5.2 used as a companion plugin for the Discy and Himer does not sanitise and escape the city phone or profile credentials fields when outputting it in the profile page allowing any authenticated user to perform Cross-Site Scripting attacks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Reference

https://wpscan.com/vulnerability/cb2fa587-da2f-460e-a402-225df7744765

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

5.4

Share on: