CVE-2022-1051
WPQA < 5.2 - Subscriber+ Stored Cross-Site Scripting via Profile fields
- Published
- May 16, 2022
- Updated
- Aug 2, 2024
- Assigning CNA
- WPScan
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NLow · next 30 days
- Percentile
- 68.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.
Sources
1WPQA < 5.2 - Subscriber+ Stored Cross-Site Scripting via Profile fields
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.