PT-2022-13705 · WordPress · Turn Off All Comments

P7E4

·

Published

2022-05-23

·

Updated

2022-05-28

·

CVE-2022-1192

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Turn off all comments WordPress plugin version 1.0
Description The issue is related to a Reflected Cross-Site Scripting problem. It occurs because the rows parameter is not properly sanitised and escaped before being outputted back in an admin page. This allows for potential malicious script injection.
Recommendations For Turn off all comments WordPress plugin version 1.0, consider disabling the admin page that outputs the rows parameter until a patch is available. Restrict access to this page to minimize the risk of exploitation. Avoid using the rows parameter in the affected admin page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1192

Affected Products

Turn Off All Comments