CVE-2021-36869
Reflected Cross-Site Scripting (XSS) vulnerability in WordPress Ivory Search plugin (versions <= 4.6.6). Vulnerable parameter: &post.
- Affected products
- Ivory Search
- Ivorysearch Ivory Search
- ≤ 4.6.6
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 0.7% (51th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2021-10-21
Fix
Update to 4.7 or higher version.
CVE-2021-36869 at NVD
1 known exploit for CVE-2021-36869
Proof-of-concept code and exploit modules indexed by Sploitus