CVE-2022-0201
MEDIUM 6.1EPSS 3.4%
The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N - EPSS
- 3.37% chance of exploitation in the next 30 days, 88th percentile
- Nuclei
- medium · CWE-79
- Published
- 2022-02-14
- Updated
- 2024-08-02