nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47982 CVE-2021-47982
MEDIUM
WordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset
Record summary
CVE-2021-47982 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the preset parameter. Attackers can submit POST requests to the plugin settings page with script payloads in the preset parameter that are stored and executed when administrators view the settings.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 8, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP-PaginateBrowse maxfoundry / WP-Paginate | CVE List | 2.1.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin WP-Paginate 2.1.3 - 'preset' Stored XSSExploitDB exploitby Park Won SeokNot analyzed1 file
References
4Product Referenceproduct
https://wordpress.org/plugins/wp-paginate ExploitDB-49355exploit
https://www.exploit-db.com/exploits/49355 VulnCheck Advisory: WordPress Plugin WP-Paginate 2.1.3 Stored XSS via presetThird-party advisory
https://www.vulncheck.com/advisories/wordpress-plugin-wp-paginate-stored-xss-via-preset