WP JS [wp-js] <= 2.0.6 (closed)
unknown
[en] The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidated user input and echoes it back to the user. This can be used for reflected Cross-Site Scripting in versions up to, and including, 2.0.6.
- Affected:
- up to 2.0.6
- Fixed in:
- 2.0.6
- Disclosed:
- May 10, 2022
CVE-2022-1567 on NVD →
WP JS <= 2.0.6 - Reflected Cross-Site Scripting
medium
The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidated user input and echoes it back to the user. This can be used for reflected Cross-Site Scripting in versions up to, and including, 2.0.6.
- CVSS:
- 6.1
- Affected:
- up to 2.0.6
- Fix:
- No patched version reported
- Disclosed:
- May 3, 2022
CVE-2022-1567 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database