S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0599 Scanner

CVE-2022-0599 scanner - Cross-Site Scripting (XSS) vulnerability in Mapping Multiple URLs Redirect Same Page plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0599
6.1
CVSS

The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Mapping multiple URLs redirect same page
5.8
Updated Aug 22, 2026View on NVD →
Detail

The Mapping Multiple URLs Redirect Same Page plugin for WordPress is a handy tool that allows website owners to redirect multiple URLs to the same page easily. This plugin is especially useful for those who have restructured their website and have changed the URLs of their pages or posts. Instead of manually adding redirects to each page, this plugin automates the process, saving time and effort.

Recently, a vulnerability has been detected in the plugin, labeled as CVE-2022-0599. The vulnerability stems from the plugin's failure to sanitize and escape the mmursp_id parameter before outputting it on an admin page. This oversight can result in Reflected Cross-Site Scripting, which can potentially allow an attacker to inject arbitrary code into a victim's browser when they click a link containing the malicious code.

The exploitation of this vulnerability can lead to various consequences, including the potential theft of sensitive information, unauthorized access to the user's website, and malware installation on the user's computer. In other words, a hacker can use this vulnerability to gain control over the user's website, steal information, compromise the user's security and that of others who visit their website.

Overall, security should be a top priority for website owners, and vulnerabilities need to be continuously monitored and addressed promptly. For those looking to receive comprehensive and automatic vulnerability reports for their websites, the pro features of s4e.io platform are highly recommended. With automatic scanning and notification features, website owners can stay one step ahead of potential vulnerabilities and ensure their website remains secure.

 

REFERENCES

Solution Advice

Fortunately, certain precautions can be taken to protect against this vulnerability. Essentially, all website owners who have installed this plugin are advised to update their website to the latest version, which contains the necessary patches to fix the vulnerability. Additionally, website owners can consider taking the following steps:

  • Install a web application firewall that can detect and block attacks.
  • Implement security protocols such as HTTPS and SSL to add an extra layer of protection to website communication.
  • Regularly scan the website for vulnerabilities and malware, using security tools and web scanners.
  • Limit the number of people who have access to website admin pages, who will have permissions to install plugins or make changes.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.