CVE-2022-1047: Themify - Post Type Builder Search Addon < 1.4.0 - Reflected Cross-Site Scripting
Published May 9, 2022
·Updated
The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.
Affected Software
1 affected component
Themify Post Type Builder Search Addon WordPress<1.4.0
Event History
May 9, 2022
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Themify Post Type Builder Search Addon WordPress plugin?
The vulnerability ID for the Themify Post Type Builder Search Addon WordPress plugin is CVE-2022-1047.
2
What is the severity of CVE-2022-1047?
The severity of CVE-2022-1047 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2022-1047?
The affected software for CVE-2022-1047 is the Themify Post Type Builder Search Addon WordPress plugin before version 1.4.0.
4
What is the CWE category for CVE-2022-1047?
The CWE category for CVE-2022-1047 is CWE-79 (Cross-Site Scripting).
5
How do I fix the vulnerability in the Themify Post Type Builder Search Addon WordPress plugin?
To fix the vulnerability in the Themify Post Type Builder Search Addon WordPress plugin, update to version 1.4.0 or later.