CVE Database /
CVE-2022-0901
CVE · Medium
CVE-2022-0901 — Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.7.12
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-0901
|
Ad Inserter – Ad Manager & AdSense Ads [ad-inserter] < 2.7.12 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.7.12
|
2.7.12 |
2022-03-14 |
—
|
CVE-2022-0901
The Ad Inserter plugin versions prior to 2.7.12 contain a reflected cross-site scripting vulnerability due to insufficient sanitization and escaping of the REQUEST_URI variable when displaying it on an administrative page. An attacker could craft a malicious link that, when clicked by an admin in certain browsers that don't automatically encode characters, would execute arbitrary JavaScript code. This vulnerability affects both the free and pro versions of the plugin up to version 2.7.11.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings