S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1933 Scanner

CVE-2022-1933 scanner - Cross-Site Scripting (XSS) vulnerability in CDI plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1933
6.1
CVSS

The CDI WordPress plugin before 5.1.9 does not sanitise and escape a parameter before outputting it back in the response of an AJAX action (available to both unauthenticated and authenticated users), leading to a Reflected Cross-Site Scripting

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
CDI – Collect and Deliver Interface for Woocommerce
AFFECTED< 5.1.9SAFE ✓≥ 5.1.9
Updated Aug 22, 2026View on NVD →
Detail

The CDI WordPress plugin is a tool used by website owners and developers to simplify the creation of custom content, designs, and functionalities for their WordPress-based websites. With this plugin, users can easily add and manage custom post types, fields, and taxonomies, as well as customize the look and feel of their sites using pre-built templates and themes.

However, recently a vulnerability was detected in the CDI WordPress plugin, specifically CVE-2022-1933, which exposes websites to a Reflected Cross-Site Scripting attack. This vulnerability arises due to the plugin's failure to sanitize and escape a parameter before outputting it back in the response of an AJAX action.

The consequences of exploiting this vulnerability can be catastrophic. Attackers can inject malicious scripts into a website and gain unauthorized access to sensitive information, such as cookies, session tokens, or even login credentials. This can lead to hijacked user accounts, data theft, website defacement, or the distribution of malware to website visitors.

Thankfully, with the pro features of the s4e.io platform, website owners and developers can easily and quickly learn about vulnerabilities in their digital assets. Through automated vulnerability scanning, threat intelligence feeds, and expert analysis, s4e.io provides a comprehensive and reliable security solution for websites of all sizes. By subscribing to the platform, you can stay ahead of the game and protect your website from emerging threats like the CVE-2022-1933 vulnerability.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners and developers should take the following precautions:

  • Update the CDI WordPress plugin to the latest version (5.1.9 or above), which contains a fix for the vulnerability.
  • Implement content security policies (CSPs) that restrict the kinds of scripts that can be run on a website.
  • Use web application firewalls (WAFs) that can detect and block malicious traffic targeting the website.
  • Conduct regular security assessments and penetration testing on the website to identify and remediate vulnerabilities before they can be exploited.
  • Train website editors and content creators on safe coding practices to avoid introducing vulnerabilities unintentionally.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.