Vulnerability Details CVE-2022-1217
The Custom TinyMCE Shortcode Button WordPress plugin through 1.1 does not sanitise and escape the PHP_SELF variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.3%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2022-1217
-
cpe:2.3:a:custom_tinymce_shortcode_button_project:custom_tinymce_shortcode_button:-
-
cpe:2.3:a:custom_tinymce_shortcode_button_project:custom_tinymce_shortcode_button:1.1