PT-2023-17427 · WordPress · Prepost Seo

Taurus Omar

·

Publicado

2023-07-10

·

Atualizado

2023-07-31

·

CVE-2023-2029

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PrePost SEO WordPress plugin versions through 3.0
Description The issue arises from the plugin's failure to properly sanitize some of its settings. This could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks, even in scenarios where the unfiltered html capability is disallowed, such as in multisite setups.
Recommendations For versions through 3.0, consider updating to a version that properly sanitizes settings to prevent Stored Cross-Site Scripting (XSS) attacks. As a temporary workaround, restrict the use of the plugin's settings to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-2029

Produtos afetados

Prepost Seo