Medium severity4.8NVD Advisory· Published May 23, 2022· Updated Jun 17, 2026
CVE-2022-1093
CVE-2022-1093
Description
The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered html is disallowed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
34.4.7+ 1 more
- (no CPE)range: 4.4.7
- cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*range: <4.4.7
- Range: <4.4.7
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/57017050-811e-474d-8256-33d19d4c0553nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.