← Back to CVE List

CVE-2022-1093

Published: 2022-05-23T08:16Z
Last Modified: 2024-11-21T06:40Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The WP Meta SEO WordPress plugin before 4.4.7 does not sanitise or escape the breadcrumb separator before outputting it to the page, allowing a high privilege user such as an administrator to inject arbitrary javascript into the page even when unfiltered html is disallowed. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt