CVE-2021-38348: Advance Search <= 1.1.2 Reflected Cross-Site Scripting
The Advance Search WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the wpasid parameter found in the ~/inc/admin/views/html-advance-search-admin-options.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Advance Search WordPress pluginfrom your environment.Uninstall the Advance Search WordPress plugin from the WordPress site (vulnerable in versions up to and including 1.1.2).
Event History
Frequently Asked Questions
What is the severity of CVE-2021-38348?
The severity of CVE-2021-38348 is considered medium due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2021-38348?
To fix CVE-2021-38348, you should update the Advance Search WordPress plugin to version 1.1.3 or later.
What is the impact of CVE-2021-38348?
The impact of CVE-2021-38348 allows attackers to inject arbitrary web scripts into the affected system.
Which versions of the Advance Search plugin are affected by CVE-2021-38348?
Versions of the Advance Search plugin up to and including 1.1.2 are affected by CVE-2021-38348.
Where can I find more information about CVE-2021-38348?
More information about CVE-2021-38348 can be found in the vulnerability advisories from security analysts.