CVE Database /
CVE-2022-4836
CVE · Medium
CVE-2022-4836 — Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types [breadcrumb] < 1.5.33
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-4836
|
Breadcrumb – Breadcrumb for WooCommerce and Custom Post Types [breadcrumb] < 1.5.33 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 1.5.33
|
1.5.33 |
2023-01-11 |
—
|
CVE-2022-4836
The Breadcrumb plugin for WooCommerce and Custom Post Types contained a cross-site scripting vulnerability in versions before 1.5.33 that could permit attackers to inject malicious scripts into a website, potentially enabling redirects, advertisements, or other HTML content to execute when visitors access the site. Researcher Lana Codes identified and disclosed this flaw. The vulnerability was resolved in version 1.5.33.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings