Vulnerability Description
The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bwp-Google-Xml-Sitemaps Project | Bwp-Google-Xml-Sitemaps | <= 1.4.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/c73316d2-ae6a-42db-935b-b8b03a7e4363ExploitThird Party Advisory
- https://wpscan.com/vulnerability/c73316d2-ae6a-42db-935b-b8b03a7e4363ExploitThird Party Advisory
FAQ
What is CVE-2022-0230?
CVE-2022-0230 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Better WordPress Google XML Sitemaps WordPress plugin through 1.4.1 does not sanitise and escape its logs when outputting them in the admin dashboard, which could allow unauthenticated users to pe...
How severe is CVE-2022-0230?
CVE-2022-0230 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0230?
Check the references section above for vendor advisories and patch information. Affected products include: Bwp-Google-Xml-Sitemaps Project Bwp-Google-Xml-Sitemaps.