Vulnerability Details CVE-2022-1549
The WP Athletics WordPress plugin through 1.1.7 does not sanitize parameters before storing them in the database, nor does it escape the values when outputting them back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.1%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2022-1549
-
cpe:2.3:a:wp_athletics_project:wp_athletics:-
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.0.0
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.0.5
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.0.6
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.1.0
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.1.1
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.1.2
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.1.3
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.1.4
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.1.5
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.1.6
-
cpe:2.3:a:wp_athletics_project:wp_athletics:1.1.7