← Vulnerability feed

Vulnerability record · CVE-2022-1597 · published 8 June 2022

CVE-2022-1597: 2code wpqa builder cross-site scripting vulnerability

2code · Wpqa Builder

The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possible to perform Reflected Cross-Site Scripting attacks

6.1 CVSS 3.1 Medium EPSS 3.0% · top 13.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The WPQA Builder WordPress plugin before 5.4, used as a companion for the Discy and Himer , does not sanitise and escape a parameter on its reset password form which makes it possible to perform Reflected Cross-Site Scripting attacks

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-1597 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-23762code wpqa builder cross-site request forgery vulnerabilityThe WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …EPSS 0.42%8.8CVE-2022-36882code wpqa builder vulnerabilityThe WPQA Builder WordPress plugin before 5.9 does not have CSRF check when following and unfollowing users, which could allow attackers to make logge…EPSS 0.51%5.4CVE-2024-23752code wpqa builder cross-site scripting vulnerabilityThe WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could allow high privilege users such …EPSS 0.33%5.4CVE-2022-10512code wpqa builder cross-site scripting vulnerabilityThe WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not sanitise and escape the city, phon…EPSS 1.3%5.3CVE-2022-15982code wpqa builder missing authentication for critical function vulnerabilityThe WPQA Builder WordPress plugin before 5.5 which is a companion to the Discy and Himer , lacks authentication in a REST API endpoint, allowing unau…EPSS 5.4%4.3CVE-2022-21982code wpqa builder insecure direct object reference vulnerabilityThe WPQA Builder WordPress plugin before 5.7 which is a companion plugin to the Hilmer and Discy , does not check authorization before displaying pri…EPSS 0.74%4.3CVE-2022-13492code wpqa builder improper authentication vulnerabilityThe WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the value passed to …EPSS 0.64%4.3CVE-2022-14252code wpqa builder insecure direct object reference vulnerabilityThe WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not validate that the message_id of th…EPSS 0.79%

Source: NIST National Vulnerability Database (record CVE-2022-1597), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.