Medium severity6.1NVD Advisory· Published Mar 7, 2022· Updated Jun 17, 2026
CVE-2021-25038
CVE-2021-25038
Description
The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:obtaininfotech:multisite_user_sync\/unsync:*:*:*:*:*:wordpress:*:*Range: <2.1.2
- WordPress/WordPress Multisite User Sync/Unsyncdescription
- Range: <2.1.2
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/72ccdcb9-3d24-41d7-b9fa-c8bd73d30aa6nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.