Medium severity6.1NVD Advisory· Published Jan 9, 2023· Updated Jun 17, 2026
CVE-2022-4301
CVE-2022-4301
Description
The Sunshine Photo Cart WordPress plugin before 2.9.15 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:sunshinephotocart:sunshine_photo_cart:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:sunshinephotocart:sunshine_photo_cart:*:*:*:*:*:wordpress:*:*range: <2.9.15
- (no CPE)range: 0
- Range: <2.9.15
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/a8dca528-fb70-44f3-8149-21385039179dnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.