CVE-2022-4321: PDF Generator for WordPress < 1.1.2 - Reflected XSS
Published Feb 6, 2023
·Updated
The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
Affected Software
1 affected component
Wpswings Pdf Generator For Wordpress Wordpress<1.1.2
Event History
Feb 6, 2023
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2022-4321?
CVE-2022-4321 is a vulnerability in the PDF Generator for WordPress plugin before version 1.1.2 that allows Reflected Cross-Site Scripting attacks.
2
How severe is CVE-2022-4321?
CVE-2022-4321 has a severity level of 6.1 (Medium).
3
Which software is affected by CVE-2022-4321?
The PDF Generator for WordPress plugin up to version 1.1.2 is affected by CVE-2022-4321.
4
How can CVE-2022-4321 be exploited?
CVE-2022-4321 can be exploited through Reflected Cross-Site Scripting, potentially targeting high privilege users like admin.
5
Is there a patch available for CVE-2022-4321?
A patch for CVE-2022-4321 is available in version 1.1.2 of the PDF Generator for WordPress plugin.