Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WordPress Newspaper theme before 12 is susceptible to cross-site scripting. The does not sanitize a parameter before outputting it back in an HTML attribute via an AJAX action. An attacker can potentially execute malware, obtain sensitive information, modify data, and/or execute unauthorized operations without entering necessary credentials. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2022/CVE-2022-2627.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-2167 | Newspaper < 12 - Reflected Cross-Site Scripting | |
| CVE-2022-2190 | Envira Gallery Lite < 1.8.4.7 - Reflected Cross-Site Scripting | |
| CVE-2022-3096 | WP Total Hacks <= 4.7.2 - Subscriber+ Arbitrary Options Update to Stored XSS | |
| CVE-2022-3237 | WP Contact Slider < 2.4.8 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-3254 | AWP Classifieds Plugin < 4.3 - Unauthenticated SQLi | |
| CVE-2022-3334 | Easy WP SMTP < 1.5.0 - Admin+ PHP Objection Injection | |
| CVE-2022-3357 | Smart Slider 3 < 3.5.1.11 - PHP Object Injection | |
| CVE-2022-3360 | LearnPress < 4.1.7.2 - Unauthenticated PHP Object Injection via REST API | |
| CVE-2022-3366 | PublishPress Capabilities < 2.5.2 - Admin+ PHP Objection Injection | |
| CVE-2022-3374 | Ocean Extra < 2.0.5 - Admin+ PHP Objection Injection | |
| CVE-2022-3380 | Customizer Export/Import < 0.9.5 - Admin+ PHP Objection Injection | |
| CVE-2022-3408 | WP Word Count <= 3.2.3 - Admin+ Stored Cross-Site Scripting | |
| CVE-2022-3419 | Automatic User Roles Switcher < 1.1.2 - Subscriber+ Privilege Escalation | |
| CVE-2022-3420 | Official Integration for Billingo < 3.4.0 - ShopManager+ Stored XSS | |
| CVE-2022-3440 | Rock Convert < 2.6.0 - Reflected Cross-Site Scripting | |
| CVE-2022-3441 | Rock Convert < 2.11.0 - Admin+ Stored Cross-Site Scripting |
No comments yet