S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0150 Scanner

CVE-2022-0150 scanner - Cross-Site Scripting (XSS) vulnerability in Accessibility Helper (WAH) plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0150
6.1
CVSS

The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WP Accessibility Helper (WAH)
AFFECTED< 0.6.0.7SAFE ✓≥ 0.6.0.7
Updated Aug 22, 2026View on NVD →
Detail

The WP Accessibility Helper (WAH) plugin for WordPress is a tool designed to make websites more accessible to people with disabilities. It provides a range of features such as text resizing, color contrast adjustment, and keyboard navigation options, among others. The plugin aims to assist website owners in complying with web accessibility standards, which can improve their user experience and help them reach a wider audience.

However, the WAH plugin has recently been found to have a serious vulnerability, known as CVE-2022-0150. This vulnerability occurs when the plugin does not sanitize and escape a parameter called wahi before outputting its base64 decode value. This leaves the plugin open to a Reflected Cross-Site Scripting (XSS) attack, where an attacker could inject malicious code into a user's session by sending them a specially crafted link.

If exploited, this vulnerability can lead to a range of negative consequences, including the theft of sensitive information or identities, the spread of malware, and even the complete takeover of a website. In some cases, an XSS attack can also be used to gain access to an organization's internal network, leading to even further compromise.

In conclusion, the WAH plugin vulnerability has the potential to pose a significant threat to website owners and their users. However, by taking appropriate precautions and staying informed about the latest security threats, website owners can minimize their risk and ensure that their sites remain safe and accessible to all users. With the pro features of s4e.io, website owners can easily and quickly learn about vulnerabilities in their digital assets, enabling them to take swift action and protect their websites from potential attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions should be taken:

  • Update the WAH plugin to the latest version (0.6.0.7 or later).
  • Ensure that all plugins and themes on your website are kept up-to-date.
  • Use a web application firewall (WAF) to block malicious requests before they reach your website.
  • Regularly scan your website for vulnerabilities using a tool like securityforeveryone.com.
  • Train your website users on how to spot and avoid phishing and other types of social engineering attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.