AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-1756

MEDIUM · CVSS 6.1 EPSS 1.79%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-06-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-1756
Severity
MEDIUM
CVSS
6.1
EPSS
1.79%
WordPress

Original NVD Description

The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER['REQUEST_URI'] before echoing it back in admin pages. Although this uses addslashes, and most modern browsers automatically URLEncode requests, this is still vulnerable to Reflected XSS in older browsers such as Internet Explorer 9 or below.