S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0201 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Permalink Manager plugin for WordPress affects v. before 2.2.15.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
6.1
CVSS
Description

The Permalink Manager Lite WordPress plugin before 2.2.15 and Permalink Manager Pro WordPress plugin before 2.2.15 do not sanitise and escape query parameters before outputting them back in the debug page, leading to a Reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Permalink Manager Liteby Maciej Bis
AFFECTED< 2.2.15SAFE ✓≥ 2.2.15
Permalink Manager Proby Maciej Bis
AFFECTED< 2.2.15SAFE ✓≥ 2.2.15
Updated Sep 18, 2026View on NVD →
Detail

Permalink Manager is a WordPress plugin designed to simplify the management of permalinks (URLs) for your website. It allows users to create custom URL structures for their posts, pages, and other content types. The plugin comes in two versions: Permalink Manager Lite and Permalink Manager Pro. Both versions provide users with the ability to manage their permalinks with ease, but the Pro version also includes additional features such as advanced redirections, custom post types, and more.

The CVE-2022-0201 vulnerability detected in Permalink Manager Lite and Pro versions before 2.2.15 stems from their failure to sanitize and escape query parameters before outputting them on the debug page. This causes a Reflected Cross-Site Scripting issue and makes it possible for attackers to inject harmful code into the website's JavaScript context. A malicious actor could potentially exploit this vulnerability to initiate phishing attacks, steal sensitive information from website visitors, or take over website user accounts.

If this vulnerability is exploited, it can lead to severe consequences for website owners and their visitors. For example, the attacker could use the vulnerability to steal user authentication credentials and gain unauthorized access to their accounts. As a result, users could be left with identity theft issues, loss of sensitive data, and financial losses. Additionally, the website owner could face legal problems and reputational damage if this issue is not fixed promptly.

s4e.io offers a powerful and efficient scanner for identifying vulnerabilities in digital assets. With its pro features, website owners can easily and quickly learn about vulnerabilities in their WordPress plugins and take necessary actions to mitigate their risks. By leveraging this tool, they can ensure that their website is secure and their visitors' data is protected from harm.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners who use Permalink Manager should update their plugins to the latest version (2.2.15 for Lite and Pro). Additionally, they can follow these precautions:

  • Use a web application firewall to detect and block malicious traffic.
  • Use a Content Security Policy (CSP) to restrict the sources of code that can be executed on the website.
  • Enable SSL/TLS encryption to ensure that data transiting between servers and clients is secure.
  • Regularly scan the website and its plugins for vulnerabilities and malware.
  • Educate users about phishing scams and how to identify and avoid them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.