← back
CVE-2022-1906CWE-79

Copyright Proof <= 4.16 - Reflected Cross-Site-Scripting

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 1.1%
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
nono source reports it
The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via an AJAX action available to both unauthenticated and authenticated users, leading to a Reflected Cross-Site Scripting when a specific setting is enabled.