CVE-2022-0448
CP Blocks < 1.0.15 - Admin+ Stored Cross-Site Scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed.
El plugin CP Blocks de WordPress versiones anteriores a 1.0.15, no sanea ni escapa de su configuración "License ID", lo que podría permitir a usuarios con altos privilegios llevar a cabo ataques de tipo Cross-Site Scripting incluso cuando el unfiltered_html no está autorizado
The CP Blocks WordPress plugin before 1.0.15 does not sanitise and escape its "License ID" settings, which could allow high privilege users to inject arbitrary web scripts that execute in a victim's browser even when the unfiltered_html is disallowed.
WordPress CP Blocks plugin version 1.0.14 suffers from a persistent cross site scripting vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-01 CVE Reserved
- 2022-02-02 CVE Published
- 2022-02-08 First Exploit
- 2023-09-28 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/50724 | 2022-02-08 | |
https://wpscan.com/vulnerability/d4ff63ee-28e6-486e-9aa7-c878b97f707c | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dwbooster Search vendor "Dwbooster" | Cp Blocks Search vendor "Dwbooster" for product "Cp Blocks" | < 1.0.15 Search vendor "Dwbooster" for product "Cp Blocks" and version " < 1.0.15" | wordpress |
Affected
|