Clipr [clipr] <= 1.2.3 (unfixed + closed)
unknown
[en] The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed
- Affected:
- up to 1.2.3
- Fix:
- No patched version reported
- Disclosed:
- May 16, 2022
CVE-2022-1559 on NVD →
Clipr <= 1.2.3 - Admin+ Stored Cross-Site Scripting
medium
The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowed
- CVSS:
- 5.9
- Affected:
- up to 1.2.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 30, 2022
CVE-2022-1559 on NVD →
Clipr [clipr] <= 1.2.3 (closed)
unknown
Stored Cross-Site Scripting (XSS) vulnerability discovered by Hassan Khan Yusufzai (Splint3r7) in WordPress Clipr plugin (versions <= 1.2.3).
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.3
- Disclosed:
- Mar 30, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database