Medium severity5.5NVD Advisory· Published Sep 23, 2021· Updated Jun 17, 2026
CVE-2021-36872
CVE-2021-36872
Description
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3). Vulnerable at &widget-wpp[2][post_type].
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=5.3.3
- Hector Cabrera/WordPress Popular Postsv5Range: 5.3.3
Patches
Vulnerability mechanics
References
2- github.com/cabrerahector/wordpress-popular-posts/blob/master/changelog.mdnvdRelease NotesThird Party Advisory
- patchstack.com/database/vulnerability/wordpress-popular-posts/wordpress-popular-posts-plugin-5-3-3-authenticated-persistent-cross-site-scripting-xss-vulnerabilitynvdThird Party Advisory
News mentions
0No linked articles in our index yet.