CVE-2022-2189

CVE-2022-2189: WP Video Lightbox < 1.9.5 - Reflected Cross-Site Scripting

Vendor Unknown
Product WP Video Lightbox
Weakness CWE-79 · XSS
Published July 25, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The WP Video Lightbox WordPress plugin before 1.9.5 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers

Key dates

02Disclosure timeline

July 25, 2022 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE