Medium severity6.1NVD Advisory· Published Mar 7, 2022· Updated Jun 17, 2026
CVE-2022-0422
CVE-2022-0422
Description
The White Label CMS WordPress plugin before 2.2.9 does not sanitise and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing, leading to a Reflected Cross-Site Scripting issue
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:videousermanuals:white_label_cms:*:*:*:*:*:wordpress:*:*Range: <2.2.9
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <2.2.9
Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changeset/2672615nvdPatchThird Party Advisory
- wpscan.com/vulnerability/429be4eb-8a6b-4531-9465-9ef0d35c12ccnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.