ARI Fancy Lightbox < 1.3.9 - Reflected Cross-Site Scripting
CVE-2022-0161
6.1MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 14 March 2022
What is CVE-2022-0161?
The ARI Fancy Lightbox WordPress plugin before 1.3.9 does not sanitise and escape the msg parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
Affected Version(s)
ARI Fancy Lightbox – WordPress Popup 1.3.9