Description
The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set.
Published: 2022-04-18
Score: 7.2 High
EPSS: 11.8% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Ad Injection Project Ad Injection
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2024-08-02T23:32:46.540Z

Reserved: 2022-02-17T00:00:00.000Z

Link: CVE-2022-0661

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-04-18T18:15:08.200

Modified: 2024-11-21T06:39:07.907

Link: CVE-2022-0661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses