CVE Database /
CVE-2022-50970
CVE · Medium
CVE-2022-50970 — AAWP [aawp] <= 3.16 (unfixed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-50970
|
AAWP [aawp] <= 3.16 (unfixed) |
— |
Medium
5.4
|
< 3.16
|
3.16 |
2026-05-10 |
—
|
CVE-2022-50970
WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the tab parameter. Attackers can craft URLs with XSS payloads in the tab parameter of the aawp-settings admin page to execute arbitrary JavaScript in the context of authenticated users.
Source:
CVE.org
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings