CVE-2022-1051 Information
Jun 07, 2022
cve
Description
The WPQA Builder Plugin WordPress plugin before 5.2 used as a companion plugin for the Discy and Himer does not sanitise and escape the city phone or profile credentials fields when outputting it in the profile page allowing any authenticated user to perform Cross-Site Scripting attacks.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Reference
https://wpscan.com/vulnerability/cb2fa587-da2f-460e-a402-225df7744765
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: