CVE-2022-0447
The Post Grid plugin prior to version 2.1.16 contains a reflected cross-site scripting vulnerability in the post_grid_update_taxonomies_terms_by_posttypes AJAX action. The post_types parameter fails to undergo proper sanitization and escaping before being reflected in the response, allowing any authenticated user to inject malicious scripts. This vulnerability exposes websites to potential session hijacking, data theft, and unauthorized actions performed on behalf of affected users.
Based on public CVE data (MITRE/NVD).