CVE-2022-4897: Ithemes Backupbuddy
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
The BackupBuddy WordPress plugin before 8.8.3 does not sanitise and escape some parameters before outputting them back in various places, leading to Reflected Cross-Site Scripting
Affected products
- Ithemes Backupbuddy: before 8.8.3 (fixed in 8.8.3)
Published 2023-02-21. Last modified 2026-06-17.