PT-2022-13724 · WordPress · Gwyn'S Imagemap Selector

P7E4

·

Published

2022-05-23

·

Updated

2022-05-28

·

CVE-2022-1221

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gwyn's Imagemap Selector WordPress plugin versions 0.3.3 and earlier
Description The issue is related to a Reflected Cross-Site Scripting problem. It occurs because some parameters are not properly sanitised and escaped before being outputted back in attributes. This can lead to malicious scripts being injected into the website.
Recommendations For Gwyn's Imagemap Selector WordPress plugin versions 0.3.3 and earlier, update to a version that properly sanitises and escapes parameters to prevent Reflected Cross-Site Scripting attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1221

Affected Products

Gwyn'S Imagemap Selector