CVE-2022-0220
WordPress GDPR & CCPA < 1.9.27 - Unauthenticated Reflected Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. Due to v1.9.26 adding a CSRF check, the XSS is only exploitable against unauthenticated users (as they all share the same nonce)
La acción check_privacy_settings AJAX del plugin GDPR de WordPress versiones anteriores a 1.9.27, disponible tanto para usuarios no autenticados como autenticados, responde con datos JSON sin un tipo de contenido "application/json". Como la carga útil HTML no es escapada correctamente, puede ser interpretada por un navegador web que conlleve a este endpoint. El código Javascript puede ser ejecutado en el navegador de la víctima. Debido a que la versión v1.9.26 añade una comprobación de tipo CSRF, un ataque de tipo XSS sólo es explotable contra usuarios no autenticados (ya que todos comparten el mismo nonce)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-13 CVE Reserved
- 2022-01-26 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-116: Improper Encoding or Escaping of Output
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/a91a01b9-7e36-4280-bc50-f6cff3e66059 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Welaunch Search vendor "Welaunch" | Wordpress Gdpr\&ccpa Search vendor "Welaunch" for product "Wordpress Gdpr\&ccpa" | <= 1.9.26 Search vendor "Welaunch" for product "Wordpress Gdpr\&ccpa" and version " <= 1.9.26" | wordpress |
Affected
|