VYPR
Medium severity4.8NVD Advisory· Published May 30, 2022· Updated Jun 17, 2026

CVE-2022-1275

CVE-2022-1275

Description

The BannerMan WordPress plugin through 0.2.4 does not sanitize or escape its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks when the unfiltered_html is disallowed (such as in multisite)

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Booster/Bannerman2 versions
    cpe:2.3:a:stillbreathing:bannerman:*:*:*:*:*:wordpress:*:*+ 1 more
    • cpe:2.3:a:stillbreathing:bannerman:*:*:*:*:*:wordpress:*:*range: <=0.2.4
    • (no CPE)range: 0.2.4
  • Range: <=0.2.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.