CVE-2022-28290
WordPress Country Selector <= 1.6.5 - Reflected Cross-Site Scripting via AJAX call of check_country_selector
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Reflective Cross-Site Scripting vulnerability in WordPress Country Selector Plugin Version 1.6.5. The XSS payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request
Una vulnerabilidad de tipo Cross-Site Scripting reflectante en el plugin Country Selector de WordPress versión 1.6.5. La carga útil de tipo XSS es ejecutada cada vez que el usuario intenta acceder a la página del selector de países con el payload especificado como parte de la petición HTTP
The Country Selector Plugin is vulnerable Cross-Site Scripting. The payload executes whenever the user tries to access the country selector page with the specified payload as a part of the HTTP request. Versions up to 1.6.5 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-03-30 CVE Published
- 2022-03-31 CVE Reserved
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-01-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://cybersecurityworks.com/zerodays/cve-2022-28290-reflected-cross-site-scripting-in-welaunch.html | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Welaunch Search vendor "Welaunch" | Wordpress Country Selector Search vendor "Welaunch" for product "Wordpress Country Selector" | 1.6.5 Search vendor "Welaunch" for product "Wordpress Country Selector" and version "1.6.5" | wordpress |
Affected
|