← back
CVE-2022-0901CWE-79

Ad Inserter < 2.7.12 - Reflected Cross-Site Scripting

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 3.5%
exploitation probability
3.5%top 12% of all CVEs
observed exploitation
nono source reports it
The Ad Inserter Free and Pro WordPress plugins before 2.7.12 do not sanitise and escape the REQUEST_URI before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters