Vulnerability Description
The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Premio | Mystickyelements | < 2.0.4 |
Related Weaknesses (CWE)
References
- https://plugins.trac.wordpress.org/changeset/2654453/mystickyelementsPatchThird Party Advisory
- https://wpscan.com/vulnerability/37665ee1-c57f-4445-9596-df4f7d72c8cdExploitThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/2654453/mystickyelementsPatchThird Party Advisory
- https://wpscan.com/vulnerability/37665ee1-c57f-4445-9596-df4f7d72c8cdExploitThird Party Advisory
FAQ
What is CVE-2022-0148?
CVE-2022-0148 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
How severe is CVE-2022-0148?
CVE-2022-0148 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0148?
Check the references section above for vendor advisories and patch information. Affected products include: Premio Mystickyelements.