CVE · Medium

CVE-2022-2181 — Advanced WordPress Reset – Debug, Recover & Reset WP [advanced-wp-reset] < 1.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2181 Advanced WordPress Reset – Debug, Recover & Reset WP [advanced-wp-reset] < 1.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 1.6 1.6 2022-07-05

CVE-2022-2181

The Advanced WordPress Reset plugin through version 1.5 contains a reflected cross-site scripting vulnerability in the DBR_new_URI parameter, which arises from improper handling of user input and failure to properly escape output. An attacker can craft a malicious link that, when clicked by a user, injects arbitrary JavaScript code into the page and executes it within their browser session. This vulnerability allows attackers to potentially steal sensitive information, modify page content, or perform actions on behalf of the victim.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.