CVE-2022-0201

The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:permalink_manager_lite_project:permalink_manager_lite:*:*:*:*:*:wordpress:*:*
cpe:2.3:a:permalink_manager_project:permalink_manager:*:*:*:*:pro:wordpress:*:*

History

No history.

Information

Published : 2022-02-14 12:15

Updated : 2024-02-28 19:09


NVD link : CVE-2022-0201

Mitre link : CVE-2022-0201

CVE.ORG link : CVE-2022-0201


JSON object : View

Products Affected

permalink_manager_lite_project

  • permalink_manager_lite

permalink_manager_project

  • permalink_manager
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')