Vulnerability Details CVE-2022-0321
The WP Voting Contest WordPress plugin before 3.0 does not sanitise and escape the post_id parameter before outputting it back in the response via the wpvc_social_share_icons AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting issue
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.8%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2022-0321
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:-
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:1.0
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:1.2
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:1.3
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:1.6
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:1.7
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:1.8
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:1.9
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:2.0
-
cpe:2.3:a:ohiowebtech:wp_voting_contest:2.1