CVE-2022-4321
PDF Generator for WordPress < 1.1.2 - Reflected XSS
Record summary
CVE-2022-4321 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PDF Generator for WordPressDefault status: unaffected | CVE List | Before 1.1.2 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMPDF Generator for WordPress < 1.1.2 - Cross Site ScriptingCVSS 6.1
The plugin includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin
Impact
Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected WordPress website, potentially leading to unauthorized access, data theft, or further compromise of the website.
Remediation
Fixed in version 1.1.2
Source: ProjectDiscovery