plugin

Automatic Pages For Privacy Policy Terms About And Contact Vulnerabilities

1 known security issue reported for the Automatic Pages For Privacy Policy Terms About And Contact WordPress plugin. Most recent disclosed Aug 1, 2022.

1 medium

Running Automatic Pages For Privacy Policy Terms About And Contact on your site? Check whether your installed version is affected.

Scan your site free

Automatic pages for Privacy Policy, Terms, About, Contact us <= 1.41 - Reflected Cross-Site Scripting

medium

The Automatic pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.41 due to the use of add_query_arg/remove_query_arg with insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

CVSS:
6.1
Affected:
up to 1.41
Fixed in:
1.42
Disclosed:
Aug 1, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database