Themify PTB Search Addon <= 1.3.9 - Reflected Cross-Site Scripting

2022-04-12 00:00
Kevin Barbón García

Strategic Overview

Status
Patched in 1.4.0
Affected Version<= 1.3.9
CVSS6.1Medium
CVECVE-2022-1047
View all Themify Post Type Builder (PTB) Search Addon vulnerabilities

Vulnerability Overview

The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.

Technical Analysis

REMEDIATION: Update to version 1.4.0, or a newer patched version --- IDENTIFIER: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C