First published: Mon Feb 06 2023(Updated: )
The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpswings Pdf Generator For Wordpress | <1.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4321 is a vulnerability in the PDF Generator for WordPress plugin before version 1.1.2 that allows Reflected Cross-Site Scripting attacks.
CVE-2022-4321 has a severity level of 6.1 (Medium).
The PDF Generator for WordPress plugin up to version 1.1.2 is affected by CVE-2022-4321.
CVE-2022-4321 can be exploited through Reflected Cross-Site Scripting, potentially targeting high privilege users like admin.
A patch for CVE-2022-4321 is available in version 1.1.2 of the PDF Generator for WordPress plugin.