Unrated severityNVD Advisory· Published May 23, 2022· Updated Aug 2, 2024
WP Meta SEO < 4.4.7 - Admin+ Stored Cross-Site Scripting via breadcrumbs
CVE-2022-1093
Description
The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered html is disallowed.
Affected products
1- Range: 4.4.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/57017050-811e-474d-8256-33d19d4c0553mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.