Medium severity4.7NVD Advisory· Published Dec 13, 2021· Updated Jun 17, 2026
CVE-2021-42548
CVE-2021-42548
Description
Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows unauthenticated user to craft a reflected Cross-Site Scripting attack.
Affected products
3cpe:2.3:a:wpcloudplugins:share-one-drive:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:wpcloudplugins:share-one-drive:*:*:*:*:*:wordpress:*:*range: <1.15.3
- (no CPE)range: unspecified
- Range: <1.15.3
Patches
Vulnerability mechanics
References
1- www.wpcloudplugins.com/wp-content/plugins/share-one-drive/_documentation/index.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.