Themify PTB Search Addon <= 1.3.9 - Reflected Cross-Site Scripting
mediumThe Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.
- CVSS:
- 6.1
- Affected:
- up to 1.3.9
- Fixed in:
- 1.4.0
- Disclosed:
- Apr 12, 2022