CVE-2022-0218 is a stored cross-site scripting (XSS) vulnerability affecting the WP HTML Mail WordPress plugin versions up to and including 3.0.9. This flaw allows unauthenticated attackers to retrieve and modify theme settings via a missing capability check on a REST-API endpoint, enabling the injection of malicious JavaScript. With a CVSS score of 6.1 (Medium) and an EPSS score indicating high exploitability, the vulnerability is easily exploited over the network with low attack complexity, potentially leading to client-side compromise. While not listed in CISA's KEV catalog, Nuclei templates exist, and it has garnered significant community discussion and media coverage, indicating a high level of awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.9CPE matchmatch criteria | cpe:2.3:a:codemiq:wordpress_email_template_designer:*:*:*:*:*:wordpress:*:* | ||
>= 3.0.9, <= 3.0.9CPE match | cpe:2.3:a:codemiq:wp_html_mail:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.