WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the preset parameter. Attackers can submit POST requests to the plugin settings page with script payloads in the preset parameter that are stored and executed when administrators view the settings.
Metrics
Affected Vendors & Products
References
History
Mon, 08 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Mon, 08 Jun 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Plugin WP-Paginate 2.1.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by manipulating the preset parameter. Attackers can submit POST requests to the plugin settings page with script payloads in the preset parameter that are stored and executed when administrators view the settings. | |
| Title | WordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset | |
| First Time appeared |
Maxfoundry
Maxfoundry wp-paginate |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:maxfoundry:wp-paginate:2.1.3:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Maxfoundry
Maxfoundry wp-paginate |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-06-08T01:55:25.110Z
Updated: 2026-06-08T16:32:56.167Z
Reserved: 2026-06-07T22:04:07.971Z
Link: CVE-2021-47982
No data.
Status : Deferred
Published: 2026-06-08T02:16:22.190
Modified: 2026-06-08T14:59:44.750
Link: CVE-2021-47982
No data.
ReportizFlow