CVE-2022-0447: Post Grid < 2.1.16 - Reflected Cross-Site Scripting via post_types
Published Apr 11, 2022
·Updated
The Post Grid WordPress plugin before 2.1.16 does not sanitise and escape the posttypes parameter before outputting it back in the response of the postgridupdatetaxonomiestermsbyposttypes AJAX action, available to any authenticated users, leading to a Reflected Cross-Site Scripting
Affected Software
1 affected component
PickPlugins Post Grid Wordpress<2.1.16
Event History
Apr 11, 2022
CVE Published
via MITRE·02:40 PM
Data Sourced
via MITRE·02:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-0447?
CVE-2022-0447 refers to a vulnerability in the Post Grid WordPress plugin before version 2.1.16.
2
What is the severity of CVE-2022-0447?
CVE-2022-0447 has a severity rating of 6.4 (Medium).
3
What is the affected software?
The affected software is the Post Grid WordPress plugin before version 2.1.16.
4
What is the CWE of CVE-2022-0447?
The CWE of CVE-2022-0447 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
5
How do I fix CVE-2022-0447?
To fix CVE-2022-0447, update the Post Grid WordPress plugin to version 2.1.16 or later.