CVE Database /
CVE-2022-25617
CVE · Medium
CVE-2022-25617 — Code Snippets [code-snippets] < 2.14.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-25617
|
Code Snippets [code-snippets] < 2.14.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 2.14.4
|
2.14.4 |
2022-05-18 |
—
|
CVE-2022-25617
The Code Snippets plugin in versions up to 2.14.3 contains a reflected cross-site scripting vulnerability affecting WordPress. An attacker can exploit this flaw by injecting malicious code through the orderby parameter, which fails to properly sanitize user input. This allows attackers to execute arbitrary JavaScript in the browsers of users who click on specially crafted links. The vulnerability was resolved in version 2.14.4.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings