CVE-2022-1047: Themify Post Type Builder Search Addon

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

The Themify Post Type Builder Search Addon WordPress plugin before 1.4.0 does not properly escape the current page URL before reusing it in a HTML attribute, leading to a reflected cross site scripting vulnerability.

Affected products

  • Themify Post Type Builder Search Addon: before 1.4.0 (fixed in 1.4.0)

Published 2022-05-09. Last modified 2026-06-17.