Medium severity5.4NVD Advisory· Published Aug 1, 2022· Updated Jun 17, 2026
CVE-2022-2171
CVE-2022-2171
Description
The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:crowdfavorite:progressive_license:*:*:*:*:*:wordpress:*:*Range: <=1.1.0
- WordPress/Progressive Licensedescription
- Range: <=1.1.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/11937296-7ecf-4b94-b274-06f7990dbedenvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.