Vulnerability Description
Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX action (available to any authenticated user), leading to a Reflected Cross-Site Scripting
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Themify | Portfolio Post | < 1.1.7 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/bbc0b812-7b30-4ab4-bac8-27c706b3f146ExploitThird Party Advisory
- https://wpscan.com/vulnerability/bbc0b812-7b30-4ab4-bac8-27c706b3f146ExploitThird Party Advisory
FAQ
What is CVE-2022-0200?
CVE-2022-0200 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Themify Portfolio Post WordPress plugin before 1.1.7 does not sanitise and escape the num_of_pages parameter before outputting it back the response of the themify_create_popup_page_pagination AJAX act...
How severe is CVE-2022-0200?
CVE-2022-0200 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0200?
Check the references section above for vendor advisories and patch information. Affected products include: Themify Portfolio Post.