HIGH

CVE-2022-0661

CVSS v3

7.2

HIGH

EPSS Score

11.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set.

Technical details

Published
4/18/2022

Frequently asked questions

What is CVE-2022-0661?

The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disallowed, leading to a stored cross-site scripting (XSS) vulnerability. Further it is also possible to inject PHP code, leading to a Remote Code execution (RCE) vulnerability, even if the DISALLOW_FILE_EDIT and DISALLOW_FILE_MOD constants are both set.

Is CVE-2022-0661 actively exploited?

Active exploitation of CVE-2022-0661 has not been confirmed. The EPSS score is 11.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2022-0661?

CVE-2022-0661 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2022-0661 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.