Vulnerabilities > CVE-2022-2071 - Unspecified vulnerability in Name Directory Project Name Directory

047910
CVSS 6.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
name-directory-project

Summary

The Name Directory WordPress plugin before 1.25.4 does not have CSRF check when importing names, and is also lacking sanitisation as well as escaping in some of the imported data, which could allow attackers to make a logged in admin import arbitrary names with XSS payloads in them.

Vulnerable Configurations

Part Description Count
Application
Name_Directory_Project
102