Unrated severityNVD Advisory· Published Jul 17, 2022· Updated Aug 3, 2024
CDI < 5.1.9 - Reflected Cross-Site-Scripting
CVE-2022-1933
Description
The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/CDIdescription
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/6cedb27f-6140-4cba-836f-63de98e521bfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.