WP Clinic
Log in Sign up

CVE · Medium

CVE-2022-50970 — AAWP [aawp] <= 3.16 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-50970 AAWP [aawp] <= 3.16 (unfixed) Medium 5.4 < 3.16 3.16 2026-05-10

CVE-2022-50970

WordPress Plugin AAWP 3.16 contains a reflected cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the tab parameter. Attackers can craft URLs with XSS payloads in the tab parameter of the aawp-settings admin page to execute arbitrary JavaScript in the context of authenticated users.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.