First published: Mon Apr 11 2022(Updated: )
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the post_types parameter before outputting it back in the response of the post_grid_update_taxonomies_terms_by_posttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Post Grid | <2.1.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0447 refers to a vulnerability in the Post Grid WordPress plugin before version 2.1.16.
CVE-2022-0447 has a severity rating of 6.4 (Medium).
The affected software is the Post Grid WordPress plugin before version 2.1.16.
The CWE of CVE-2022-0447 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
To fix CVE-2022-0447, update the Post Grid WordPress plugin to version 2.1.16 or later.