S4E just found a medium-severity finding from http usage detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 8, 2024

CVE-2022-45365 Scanner

CVE-2022-45365 scanner - Cross-Site-Scripting vulnerability in Stock Ticker

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-45365
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
Stock Tickerby Aleksandar Urošević
n/a
Updated Aug 22, 2026View on NVD →
Detail

The Stock Ticker WordPress plugin is a tool used by website owners to display real-time stock ticker information on their WordPress sites. It's designed for financial bloggers, investment advisors, or anyone interested in showing live stock market data. This plugin fetches data from various stock exchanges and presents it in a customizable ticker format, allowing site visitors to stay updated with the latest stock prices and market trends. Its features include customizable appearance, support for multiple stock exchanges, and the ability to display specific stocks or global market indexes.

CVE-2022-45365 discloses a reflected Cross-Site Scripting (XSS) vulnerability found in versions up to and including 3.23.2 of the Stock Ticker WordPress plugin. This vulnerability arises due to insufficient input sanitization and output escaping in the ajax_stockticker_symbol_search_test function. Unauthenticated attackers can exploit this flaw by crafting malicious URLs that, when clicked by a user, execute arbitrary web scripts in the user's browser context.

The vulnerability specifically exists in the way the Stock Ticker plugin handles AJAX requests through the /wp-admin/admin-ajax.php endpoint. An attacker can inject malicious scripts into the 'symbol' and 'endpoint' parameters of a POST request. These scripts are then reflected back in the response from the server and executed in the context of the user's browser session. The attack can lead to unauthorized actions being performed on behalf of the user, data theft, or redirection to malicious websites.

The exploitation of this XSS vulnerability could lead to a range of security issues including session hijacking, phishing attacks, theft of sensitive information, and the spread of malware. Users could be tricked into executing unauthorized actions on the website, potentially compromising their security and privacy, as well as the integrity of the website itself.

By leveraging the security scanning services offered by S4E, users can protect their WordPress sites against vulnerabilities like CVE-2022-45365 in the Stock Ticker plugin. Our platform provides thorough vulnerability assessments, real-time monitoring, and actionable recommendations to mitigate risks. Joining S4E ensures that your digital assets are continuously protected from emerging threats, helping you maintain trust with your site visitors and safeguard your online presence.

 

References

Solution Advice
  1. Update the Stock Ticker plugin to version 3.23.3 or later, which contains a fix for the vulnerability.
  2. Always sanitize and escape user inputs and outputs to prevent XSS attacks.
  3. Use security plugins that offer additional protections against common web vulnerabilities.
  4. Regularly audit your WordPress site and plugins for security updates and vulnerabilities.
  5. Educate users about the importance of cautious web browsing, especially when following links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-45365 scanner - Cross-Site-Scripting vulnerability in Stock Ticker | S4E