CVE · Medium

CVE-2021-33852 — Post Duplicator [post-duplicator] < 2.27

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-33852 Post Duplicator [post-duplicator] < 2.27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.27 2.27 2021-12-02

CVE-2021-33852

The Post Duplicator plugin before version 2.27 contains a cross-site scripting vulnerability where malicious JavaScript code entered in the "Duplicate Title" field will execute when users access either the plugin's Settings Page or the application root page following a post duplication action. This flaw allows attackers to run arbitrary scripts in the browsers of affected users by injecting code through the vulnerable text field.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.