Vulnerability Description
The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Searchiq | Searchiq | < 3.9 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/0ee7d1a8-9782-4db5-b055-e732f2763825ExploitThird Party Advisory
- https://wpscan.com/vulnerability/0ee7d1a8-9782-4db5-b055-e732f2763825ExploitThird Party Advisory
FAQ
What is CVE-2022-0780?
CVE-2022-0780 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform ...
How severe is CVE-2022-0780?
CVE-2022-0780 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-0780?
Check the references section above for vendor advisories and patch information. Affected products include: Searchiq Searchiq.