CVE · Medium

CVE-2022-0447 — Post Grid [post-grid] < 2.1.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0447 Post Grid [post-grid] < 2.1.16 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 2.1.16 2.1.16 2022-03-15

CVE-2022-0447

The Post Grid plugin prior to version 2.1.16 contains a reflected cross-site scripting vulnerability in the post_grid_update_taxonomies_terms_by_posttypes AJAX action. The post_types parameter fails to undergo proper sanitization and escaping before being reflected in the response, allowing any authenticated user to inject malicious scripts. This vulnerability exposes websites to potential session hijacking, data theft, and unauthorized actions performed on behalf of affected users.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.