CVE-2022-1756 describes a Reflected Cross-Site Scripting (XSS) vulnerability in The Newsletter WordPress plugin versions prior to 7.4.5. The flaw stems from insufficient sanitization of the $_SERVER['REQUEST_URI'] before it's echoed back in administrative pages, making it exploitable in older browsers like Internet Explorer 9 or below. This vulnerability has a CVSS score of 6.1 (Medium), indicating a low attack complexity and requiring user interaction, with potential impacts on confidentiality and integrity. The FAUCET Risk Score is 84/100, suggesting a notable risk despite the medium CVSS. Currently, there is no evidence of active exploitation, and it is not listed in CISA's KEV catalog. While no Metasploit modules or ExploitDB entries exist, Nuclei templates are available for detection. Community discussion and media coverage are minimal, typical for the vast majority of CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.4.5CPE matchmatch criteria | cpe:2.3:a:thenewsletterplugin:newsletter:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.