CVE-2022-0422 describes a Reflected Cross-Site Scripting (XSS) vulnerability in the White Label CMS WordPress plugin prior to version 2.2.9. This flaw arises from insufficient sanitization and validation of the wlcms[_login_custom_js] parameter, allowing malicious scripts to be injected into the response during preview. Rated as Medium severity with a CVSS score of 6.1, this vulnerability requires user interaction (UI:R) for exploitation and can lead to low impact on confidentiality and integrity (C:L/I:L). An attacker could leverage this to execute arbitrary client-side scripts in the victim's browser. Currently, there is no evidence of active exploitation, and it is not listed in CISA's KEV catalog. While Nuclei templates exist for detection, there are no public Metasploit modules or ExploitDB entries, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.9CPE matchmatch criteria | cpe:2.3:a:videousermanuals:white_label_cms:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.