CVE-2022-4321

CVE-2022-4321: PDF Generator for WordPress < 1.1.2 - Reflected XSS

Vendor Unknown
Product PDF Generator for WordPress
Published February 6, 2023
Last update March 26, 2025

CVSS base score

What the vulnerability does

01Description

The PDF Generator for WordPress plugin before 1.1.2 includes a vendored dompdf example file which is susceptible to Reflected Cross-Site Scripting and could be used against high privilege users such as admin

Key dates

02Disclosure timeline

February 6, 2023 CVE published
March 26, 2025 Record updated