← Back to CVE List

CVE-2022-0431

Published: 2022-04-04T16:15Z
Last Modified: 2024-11-21T06:38Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The Insights from Google PageSpeed WordPress plugin before 4.0.4 does not sanitise and escape various parameters before outputting them back in attributes in the plugin's settings dashboard, leading to Reflected Cross-Site Scripting > MITRE Terms of Use apply – see LICENSE‑MITRE.txt