Medium severity6.1NVD Advisory· Published May 9, 2022· Updated Jun 17, 2026
CVE-2022-1047
CVE-2022-1047
Description
The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<1.4.0+ 1 more
- (no CPE)range: <1.4.0
- (no CPE)
- cpe:2.3:a:themify:post_type_builder_search_addon:*:*:*:*:*:wordpress:*:*Range: <1.4.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/078bd5f6-64f7-4665-825b-9fd0c2b7b91bnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.