Medium severity6.1NVD Advisory· Published Jul 17, 2022· Updated Jun 17, 2026
CVE-2022-1933
CVE-2022-1933
Description
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:collect_and_deliver_interface_for_woocommerce_project:collect_and_deliver_interface_for_woocommerce:*:*:*:*:*:wordpress:*:*Range: <5.1.9
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/6cedb27f-6140-4cba-836f-63de98e521bfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.