First published: Mon Feb 28 2022(Updated: )
The WP-Paginate WordPress plugin before 2.1.4 does not sanitise and escape its preset settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Maxfoundry Wp-paginate | <2.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4222 has a medium severity level due to its potential to allow Cross-Site Scripting (XSS) attacks.
To fix CVE-2021-4222, update the WP-Paginate plugin to version 2.1.4 or later.
CVE-2021-4222 affects all versions of the WP-Paginate WordPress plugin prior to 2.1.4.
CVE-2021-4222 impacts high privilege users, such as administrators, of WordPress sites using the affected plugin.
CVE-2021-4222 facilitates Cross-Site Scripting (XSS) attacks due to improper sanitization and escaping of settings.