CVE-2022-1910CWE-79

CVE-2022-1910: vulnerability in Shortcodes and extra features for Phlox theme

Shortcodes and extra features for Phlox theme < 2.9.8 - Reflected Cross-Site-Scripting

Published · Updated

18Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 1.4%
exploitation probability
1.4%top 28% of all CVEs
observed exploitation
nono source reports it
The Shortcodes and extra features for Phlox WordPress plugin before 2.9.8 does not sanitise and escape a parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting
Related CVEs — Shortcodes and extra features for Phlox theme

In the same product, most dangerous first.