First published: Mon Jan 17 2022(Updated: )
The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
PluginOps Landing Page Builder | <1.4.9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Landing Page Builder WordPress plugin is CVE-2021-25067.
The severity of CVE-2021-25067 is medium with a CVSS score of 5.4.
The Landing Page Builder WordPress plugin version 1.4.9.6 and earlier are affected.
CVE-2021-25067 is a reflected XSS vulnerability.
To fix CVE-2021-25067, update the Landing Page Builder WordPress plugin to version 1.4.9.7 or later.