Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-1051 — WPQA < 5.2 - Subscriber+ Stored Cross-Site Scripting via Profile fields | Kitploit
Tools/GitHubGitHub/v35hr4j/cve-2022-1051
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & Education
GitHubv35hr4j/cve-2022-1051

CVE-2022-1051

WPQA < 5.2 - Subscriber+ Stored Cross-Site Scripting via Profile fields

View Repository
24 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-1051

WPQA < 5.2 - Subscriber+ Stored Cross-Site Scripting via Profile fields

Description

The plugin, used as a companion plugin for the Discy and Himer themes, does not sanitise and escape the city, phone or profile credentials fields when outputting it in the profile page, allowing any authenticated user to perform Cross-Site Scripting attacks.

Proof of Concept

Edit your profile and add the following payload in one of the unescaped fields. `````` Upon visiting your profile, XSS will be triggered

Fixed in version 5.2

References:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1051

https://wpscan.com/vulnerability/cb2fa587-da2f-460e-a402-225df7744765

Video POC:

https://www.youtube.com/watch?v=hoy9MYoki7k

Download Tool