S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1221 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Gwyn's Imagemap Selector plugin for WordPress affects v. through 0.3.3.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1221
6.1
CVSS

The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Gwyn's Imagemap Selector
0.3.3
Updated Aug 22, 2026View on NVD →
Detail

Gwyn's Imagemap Selector is a plugin developed for WordPress users to create image maps. These image maps are used to specify different clickable regions within an image, allowing website visitors to interact with graphical content in an intuitive way. The plugin's user-friendly interface and customizable features make it a popular option among web developers and designers looking to add interactivity to their websites.

Among its many features, Gwyn's Imagemap Selector has been found to have a vulnerability, referred to as CVE-2022-1221. This vulnerability arises because certain parameters are not sanitized and escaped before being outputted, which can allow attackers to execute Reflected Cross-Site Scripting attacks.

Reflected Cross-Site Scripting is a type of vulnerability that allows attackers to inject malicious code into web pages, which is then executed when users visit the page. When exploited, this vulnerability could allow attackers to steal user credentials, cookies and other sensitive information. Furthermore, attackers could also use this vulnerability to take control of the website and deface it or even inject malicious links or malware into the site's pages, thereby infecting the visitors' computers.

In conclusion, it is important to be aware of this vulnerability in Gwyn's Imagemap Selector plugin, as it has the potential to cause significant harm to websites if left unaddressed. The pro features of the s4e.io platform make it easy to identify and assess vulnerabilities in digital assets, ensuring that website administrators can mitigate risk to their sites and users quickly and effectively.

 

REFERENCES

Solution Advice

In order to protect against this vulnerability, it is recommended that website administrators take a few different precautions. Some of these are bullet-listed below:

  • Upgrade to the latest version of Gwyn's Imagemap Selector plugin which contains fixes for the vulnerability.
  • Consider using an alternate plugin that does not have this vulnerability.
  • Use a web application firewall (WAF) which can help detect and block malicious traffic attempting to exploit this vulnerability.
  • Train website developers in secure coding practices, such as sanitizing and escaping user input before outputting it to prevent such vulnerabilities.
  • Ensure website users are educated on how to use the website securely, such as warning them when clicking on links that appear suspicious.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-1221 scanner - Cross-Site Scripting (XSS) vulnerability in Gwyn's Imagemap Selector plugin for WordPress | S4E