Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-2189


The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers


Published

2022-07-25T13:15:08.413

Last Modified

2024-11-21T07:00:30.567

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application tipsandtricks-hq wp_video_lightbox < 1.9.5 Yes

References