6.1
CVE-2022-2311
- EPSS 0.2%
- Veröffentlicht 28.11.2022 14:15:11
- Zuletzt bearbeitet 23.04.2025 17:15:46
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Find and Replace All <= 1.3 - Cross-Site Request Forgery to Reflected Cross-Site Scripting
The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue.
Mögliche Gegenmaßnahme
Find and Replace All: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Find and Replace All
Version
*-1.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Find And Replace All Project ≫ Find And Replace All SwPlatformwordpress Version < 1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.422 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|