Medium severity6.1NVD Advisory· Published May 9, 2022· Updated Jun 17, 2026
CVE-2022-1047
CVE-2022-1047
Description
The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:themify:post_type_builder_search_addon:*:*:*:*:*:wordpress:*:*Range: <1.4.0
- WordPress/Themify Post Type Builder Search Addon WordPress plugindescription
- Range: <1.4.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/078bd5f6-64f7-4665-825b-9fd0c2b7b91bnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.