Junglewise Threat Intelligence

CVE-2021-47982: Max Foundry WP-Paginate stored XSS in preset parameter

CVE-2021-47982 · Severity: medium · CVSS 6.4 · Published 2026-06-08

Executive brief

WP-Paginate is a WordPress plugin used to improve website navigation and SEO by adding pagination to posts and comments. A security flaw allows an attacker with basic account access to inject malicious scripts into the plugin's settings. These scripts are then executed when a site administrator views the settings page, potentially leading to unauthorized administrative actions or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in WP-Paginate version 2.1.3 and earlier due to improper neutralization of the 'preset' parameter in the plugin settings. An authenticated attacker can send a specially crafted POST request to the plugin's settings page (wp-admin/options-general.php?page=wp-paginate.php) containing a malicious script payload. This payload is stored in the database and executed in the context of an administrator's browser session when they visit the settings page. This can lead to session hijacking or unauthorized configuration changes. While the vulnerability was disclosed in 2021, users should ensure they have updated to a version beyond 2.1.3.

Affected products

  • Max Foundry WP-Paginate 2.1.3 and earlier

Timeline

  • 2021-01-04: disclosed: Original exploit discovery and report by Park Won Seok
  • 2021-01-05: other: Exploit published on Exploit-DB
  • 2026-06-08: advisory: CVE published to NVD dataset

References