S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0535 Scanner

CVE-2022-0535 scanner - Cross-Site Scripting (XSS) vulnerability in E2Pdf plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0535
4.8
CVSS

The E2Pdf WordPress plugin before 1.16.45 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
E2Pdf – Export To Pdf Tool for WordPress
AFFECTED< 1.16.45SAFE ✓≥ 1.16.45
Updated Aug 22, 2026View on NVD →
Detail

The E2Pdf WordPress plugin is a tool utilized by website administrators to easily convert WordPress data into PDF format. This plugin is commonly used to create professional and customized PDF documents such as invoices, receipts, and order confirmations. The plugin is designed to simplify the conversion process by providing a user-friendly interface that allows administrators to choose the data they wish to convert and customize the output to meet their specific needs.

One vulnerability that has been discovered in the E2Pdf WordPress plugin is the CVE-2022-0535 vulnerability. This vulnerability occurs when the plugin fails to sanitize and escape certain settings, which can allow high privilege users to execute Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed. Attackers can exploit this vulnerability to inject malicious code into compromised websites and steal sensitive user data or propagate malware.

The exploitation of the CVE-2022-0535 vulnerability can lead to various cybersecurity risks. Attackers can use the vulnerability to hijack user sessions, install malware on the website, or steal confidential information such as usernames, passwords, and credit card details. Furthermore, the vulnerability can lead to reputation damage for the website and its administrator as the website can be labeled as insecure, leading to loss of visitors and trust.

In conclusion, the CVE-2022-0535 vulnerability poses a significant threat to websites that use the E2Pdf WordPress plugin. Website administrators should take immediate measures to mitigate the risk by following the precautions mentioned above. By using the pro features of the s4e.io platform, website administrators can quickly and easily stay updated on vulnerabilities in their digital assets and ensure that their websites are protected from threats.

 

REFERENCES

Solution Advice

To protect against the CVE-2022-0535 vulnerability, website administrators should take the following precautions:

  • Update the E2Pdf WordPress plugin to the latest version that addresses the vulnerability
  • Use a web application firewall to block XSS attacks
  • Implement strict input validation and encoding practices to prevent untrusted user input from being processed
  • Use Content Security Policy (CSP) to prevent browsers from executing any unsafe scripts
  • Monitor web traffic for any suspicious activity and immediately block attempts to exploit the vulnerability.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.