PT-2022-13720 · WordPress · Custom Tinymce Shortcode Button
P7E4
·
Published
2022-05-16
·
Updated
2022-05-24
·
CVE-2022-1217
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Custom TinyMCE Shortcode Button WordPress plugin versions 1.1 and earlier
Description
The issue arises from the lack of sanitization and escaping of the
PHP SELF variable before it is outputted in an attribute on an admin page, leading to Reflected Cross-Site Scripting.Recommendations
For Custom TinyMCE Shortcode Button WordPress plugin versions 1.1 and earlier, update to a version that properly sanitizes and escapes the
PHP SELF variable to prevent Reflected Cross-Site Scripting.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Custom Tinymce Shortcode Button