CVE-2022-1707
The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 89.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The Google Tag Manager for WordPress plugin for WordPress is vulnerable to reflected Cross-Site Scripting via the s parameter due to the site search populating into the data layer of sites with insufficient sanitization in versions up to an including 1.15. The affected file is ~/public/frontend.php and this could be exploited by unauthenticated attackers.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 89.28% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- gtm4wp/google tag manager
- Source
- security@wordfence.com
References
- https://github.com/duracelltomi/gtm4wp/blob/1.15/public/frontend.php#L298Product
- https://github.com/duracelltomi/gtm4wp/blob/1.15/public/frontend.php#L782Product
- https://github.com/duracelltomi/gtm4wp/issues/224Issue Tracking
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0435ae14-c1fd-4611-acbe-5f3bafd4bb6a?source=cveThird Party Advisory
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1707Third Party Advisory
- https://github.com/duracelltomi/gtm4wp/blob/1.15/public/frontend.php#L298Product
- https://github.com/duracelltomi/gtm4wp/blob/1.15/public/frontend.php#L782Product
- https://github.com/duracelltomi/gtm4wp/issues/224Issue Tracking
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0435ae14-c1fd-4611-acbe-5f3bafd4bb6a?source=cveThird Party Advisory
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-1707Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.