S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-1906 Scanner

CVE-2022-1906 scanner - Cross-Site Scripting (XSS) vulnerability in Copyright Proof plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-1906
6.1
CVSS

The Copyright Proof WordPress plugin through 4.16 does not sanitise and escape a parameter before outputting it back via an AJAX action available to both unauthenticated and authenticated users, leading to a Reflected Cross-Site Scripting when a specific setting is enabled.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Copyright Proof
4.16
Updated Aug 22, 2026View on NVD →
Detail

The Copyright Proof plugin for WordPress is a tool used to prove ownership of copyrighted material on a website. This plugin allows the website owner to display a digital proof of copyright on their website, reassuring their audience of the originality of their content. The plugin accomplishes this by creating a digital fingerprint of the website's content and storing it in a database for future reference.

The CVE-2022-1906 vulnerability detected in the Copyright Proof plugin for WordPress is a Reflected Cross-Site Scripting (XSS) vulnerability. This vulnerability arises because the plugin does not properly sanitize and escape a parameter before outputting it back. This parameter is available through an AJAX action that is accessible to both authenticated and unauthenticated users. When a specific setting is enabled, an attacker can inject malicious code into the parameter, leading to a reflected XSS attack.

Exploiting this vulnerability can lead to a range of consequences, depending on the attacker's motives and the website's content. If the victim is a large enterprise, the attacker can use the XSS attack to gain access to sensitive data, plant malware, or steal credentials. If the victim is an individual, the attacker might use the XSS attack to redirect the victim to a phishing site or to cause damage to the website.

Thanks to the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. With real-time alerts and remediation guidance, the platform helps website owners stay ahead of emerging threats and keep their websites secure. Protect your website today and safeguard your online presence with s4e.io.

 

REFERENCES

Solution Advice

To protect against the CVE-2022-1906 vulnerability in the Copyright Proof plugin for WordPress, website owners should take the following precautions:

  • Update the Copyright Proof plugin to the latest version, which addresses the vulnerability.
  • Implement a Web Application Firewall (WAF) that can detect and block XSS attacks.
  • Use Content Security Policies (CSPs) to limit the sources of trusted content and prevent malicious code injection.
  • Educate website administrators and users on the risks of XSS attacks and best practices for avoiding them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-1906 scanner - Cross-Site Scripting (XSS) vulnerability in Copyright Proof plugin for WordPress | S4E