CVE-2022-0661
The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 40.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 40.24% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- ad injection project/ad injection
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/3c5a7b03-d4c3-46b9-af65-fb50e58b0bfdExploit, Third Party Advisory
- https://wpscan.com/vulnerability/3c5a7b03-d4c3-46b9-af65-fb50e58b0bfdExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.