Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-65201
HistoryJun 01, 2022 - 12:00 a.m.

WordPress WP 2FA plugin cross-site scripting vulnerability

2022-06-0100:00:00
China National Vulnerability Database
www.cnvd.org.cn
21
wordpress
php
plugin
vulnerability
xss
client-side
attack
version 2.2.1

EPSS

0.001

Percentile

40.2%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a set of blogging platforms developed using the PHP language. WordPress plugin is an application plugin. WordPress WP 2FA plugin version 2.2.1 before version 2.2.1 has a cross-site scripting vulnerability that stems from parameters that are not properly cleaned and escaped when passed back to the admin page. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

40.2%