CVE Feed

    Dashboard / CVE / CVE-2022-0661

    CVE-2022-0661

    The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set.

    Published:Apr 18, 2022
    Last Modified:Nov 21, 2024
    EPS:Apr 18, 2022
    EPSS Score:0.18306
    CVSS Score:7.2

    Affected Products

    Vendor
    Ad Injection Project
    Product
    Ad Injection

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High