### [CVE-2022-1569](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1569) ![](https://img.shields.io/static/v1?label=Product&message=Drag%20%26%20Drop%20Builder%2C%20Human%20Face%20Detector%2C%20Pre-built%20Templates%2C%20Spam%20Protection%2C%20User%20Email%20Notifications%20%26%20more!&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=1.4.9.4%3C%201.4.9.4%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-79%20Cross-site%20Scripting%20(XSS)&color=brighgreen) ### Description The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is disallowed ### POC #### Reference - https://wpscan.com/vulnerability/5a2756c1-9abf-4fd6-8ce2-9f840514dfcc #### Github No PoCs found on GitHub currently.