.. / CVE-2022-2627

Exploit for WordPress Newspaper < 12 - Cross-Site Scripting (CVE-2022-2627)

Description:

WordPress Newspaper theme before 12 is susceptible to cross-site scripting. The does not sanitize a parameter before outputting it back in an HTML attribute via an AJAX action. An attacker can potentially execute malware, obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials.

Nuclei Template

View the template here CVE-2022-2627.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-2627.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2022-2627
https://wpscan.com/vulnerability/038327d0-568f-4011-9b7e-3da39e8b6aea