Vulnerability Description
Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Welaunch | Wordpress Country Selector | 1.6.5 |
Related Weaknesses (CWE)
References
- https://cybersecurityworks.com/zerodays/cve-2022-28290-reflected-cross-site-scriExploitThird Party Advisory
- https://cybersecurityworks.com/zerodays/cve-2022-28290-reflected-cross-site-scriExploitThird Party Advisory
FAQ
What is CVE-2022-28290?
CVE-2022-28290 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specifie...
How severe is CVE-2022-28290?
CVE-2022-28290 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-28290?
Check the references section above for vendor advisories and patch information. Affected products include: Welaunch Wordpress Country Selector.