CVE-2022-2171
Estado: ModificadaMedia (5.4)—
The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.31%
- Percentil entre todas las CVEs puntuadas: 22
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-352
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-2171",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "contact@wpscan.com",
"affectedData": [
{
"vendor": "Unknown",
"product": "Progressive License",
"versions": [
{
"status": "affected",
"version": "1.1.0",
"versionType": "custom",
"lessThanOrEqual": "1.1.0"
}
]
}
]
}
],
"published": "2022-08-01T13:15:10.513",
"references": [
{
"url": "https://wpscan.com/vulnerability/11937296-7ecf-4b94-b274-06f7990dbede",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/11937296-7ecf-4b94-b274-06f7990dbede",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "contact@wpscan.com",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Progressive License WordPress plugin through 1.1.0 is lacking any CSRF check when saving its settings, which could allow attackers to make a logged in admin change them. Furthermore, as the plugin allows arbitrary HTML to be inserted in one of the settings, this could lead to Stored XSS issue which will be triggered in the frontend as well."
},
{
"lang": "es",
"value": "El plugin Progressive License de WordPress versiones hasta 1.1.0 carece de cualquier comprobación de tipo CSRF cuando guarda sus ajustes, lo que podría permitir a atacantes hacer que un administrador conectado los cambie. Además, como el plugin permite insertar HTML arbitrario en una de las configuraciones, esto podría conllevar a un problema de tipo XSS almacenado que sería desencadenado también en el frontend"
}
],
"lastModified": "2026-06-17T04:41:26.187",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:crowdfavorite:progressive_license:*:*:*:*:*:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "A7286275-18BF-40B4-959F-2243ADFCB56B",
"versionEndIncluding": "1.1.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "contact@wpscan.com"
}