CVE-2022-2654
Published: Sep 16, 2022
Modified: Jun 5, 2025
Description
The Classima WordPress theme before 2.1.11 and some of its required plugins (Classified Listing before 2.2.14, Classified Listing Pro before 2.0.20, Classified Listing Store & Membership before 1.4.20 and Classima Core before 1.10) do not escape a parameter before outputting it back in attributes, leading to Reflected Cross-Site Scripting
| Vendor | Product | Versions |
|---|---|---|
Unknown | Classified Listing – Classified ads & Business Directory Plugin | affected 2.2.14 - < 2.2.14 |
Unknown | Classified Listing Pro - Classified ads & Business Directory Plugin | affected 2.0.20 - < 2.0.20 |
Unknown | Classified Listing Store & Membership Addon | affected 1.4.20 - < 1.4.20 |
Unknown | Classima Core | affected 1.10 - < 1.10 |
Unknown | Classima | affected 2.1.11 - < 2.1.11 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now