CVE-2022-0150
28.02.2022, 09:15
The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue
Vendor | Product | Version |
---|---|---|
wp_accessibility_helper_project | wp_accessibility_helper | 𝑥 < 0.6.0.7 |
𝑥
= Vulnerable software versions