CVE Database /
CVE-2022-3934
CVE · Medium
CVE-2022-3934 — FlatPM – Ad Manager, AdSense and Custom Code [flatpm-wp] < 2.662
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3934
|
FlatPM – Ad Manager, AdSense and Custom Code [flatpm-wp] < 2.662 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 3.0.13
|
3.0.13 |
2022-11-17 |
—
|
CVE-2022-3934
The FlatPM plugin for WordPress through version 2.661 contains a reflected cross-site scripting vulnerability caused by inadequate sanitization and escaping of the block_cat_ID parameter. An unauthenticated attacker could craft a malicious link containing arbitrary JavaScript code that executes in an administrator's browser if the admin is tricked into clicking it. This allows injection of malicious scripts into pages viewed by administrators who interact with the attacker's crafted URL.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings