← back
CVE-2022-1221observed exploitationCWE-79

Gwyn's Imagemap Selector <= 0.3.3 - Reflected Cross-Site Scripting

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 2.1%
from disclosure to weapon
Published on NVDMay 23
VulnCheck+1112d
exploitation probability
2.1%top 20% of all CVEs
observed exploitation
yesVulnCheck
The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.