← volver
CVE-2022-0150

WP Accessibility Helper (WAH) < 0.6.0.7 - Reflected Cross-Site Scripting (XSS)

EPSS 1.7%CWE-79
The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →