Classima < 2.1.11 - Reflected Cross-Site Scripting
CVE-2022-2654

6.1MEDIUM

Summary

The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting

Affected Version(s)

Classified Listing – Classified ads & Business Directory Plugin 2.2.14

Classified Listing Pro - Classified ads & Business Directory Plugin 2.0.20

Classified Listing Store & Membership Addon 1.4.20

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Team ISH Tecnologia (Thiago Martins
Jorge Buzeti
Leandro Inacio
Lucas de Souza
Matheus Oliveira
Filipe Baptistella
Leonardo Paiva
Jose Thomaz
Joao Maciel
Vinicius Pereira
Geovanni Campos
Hudson Nowak
Guilherme Acerbi) and Islan Ferreira.
.