Record summary

CVE-2022-4321 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 26, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

PDF Generator for WordPress

Default status: unaffected

CVE ListBefore 1.1.2affected

Nuclei templates

1
ProjectDiscoveryMEDIUMPDF Generator for WordPress < 1.1.2 - Cross Site ScriptingCVSS 6.1

The plugin includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected WordPress website, potentially leading to unauthorized access, data theft, or further compromise of the website.

Remediation

Fixed in version 1.1.2

WeaknessesCWE-79
Authorsr3Y3r53, HuTa0
Template tagscvecve2022wpscanwordpresswpwp-pluginxsspdf-generator-for-wpwpswingsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wpswings:pdf_generator_for_wordpress:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/pdf-generator-for-wp
FOFA: body=/wp-content/plugins/pdf-generator-for-wp

Source: ProjectDiscovery

References

2