PT-2023-21886 · WordPress · Meta Data/Taxonomies Filter

Joshua Martinelle

·

Publicado

2023-03-22

·

Atualizado

2023-03-28

·

CVE-2023-28664

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Meta Data and Taxonomies Filter WordPress plugin versions prior to 1.3.1
Description The issue is a reflected cross-site scripting vulnerability in the tax name parameter of the mdf get tax options in widget action. This can only be triggered by an authenticated user.
Recommendations For versions prior to 1.3.1, update to version 1.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the mdf get tax options in widget action to minimize the risk of exploitation. Avoid using the tax name parameter in the affected action until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28664

Produtos afetados

Meta Data/Taxonomies Filter