Headline
CVE-2022-36357: WordPress ULTIMATE TABLES plugin <= 1.6.5 - Unauth. Reflected Cross-Site Scripting (XSS) vulnerability - Patchstack
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ULTIMATE TABLES plugin <= 1.6.5 on WordPress.
Verified
Not fixed
6.1
CVSS 3.1 score Medium severity
Report
Monitoring Not reported to be exploited
Vulnerable versions
<= 1.6.5
PSID
ce597319e58f
Classification
Cross Site Scripting (XSS)
OWASP Top 10
A7: Cross-Site Scripting (XSS)
Publicly disclosed
2022-11-17
Details
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability discovered by Tien Nguyen Anh (Patchstack Alliance) in WordPress ULTIMATE TABLES plugin (versions <= 1.6.5).
Solution
No patched version is available. No reply from the vendor.
References