CVE-2022-3209

CVE-2022-3209: Soledad < 8.2.5 - Reflected Cross-site Scripting

Vendor Unknown
Product soledad
Weakness CWE-79 · XSS
Published October 10, 2022
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

Key dates

02Disclosure timeline

October 10, 2022 CVE published
August 3, 2024 Record updated