.. / CVE-2022-0422

Exploit for WordPress White Label CMS <2.2.9 - Cross-Site Scripting (CVE-2022-0422)

Description:

WordPress White Label CMS plugin before 2.2.9 contains a reflected cross-site scripting vulnerability. It does not sanitize and validate the wlcms[_login_custom_js] parameter before outputting it back in the response while previewing.

Nuclei Template

View the template here CVE-2022-0422.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-0422.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://plugins.trac.wordpress.org/changeset/2672615
https://github.com/ARPSyndicate/kenzer-templates
https://wpscan.com/vulnerability/429be4eb-8a6b-4531-9465-9ef0d35c12cc
https://nvd.nist.gov/vuln/detail/CVE-2022-0422