PT-2023-16768 · WordPress · Wp-Optimize+1

Paolo Elia

·

Published

2023-07-10

·

Updated

2025-01-06

·

CVE-2023-1119

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP-Optimize WordPress plugin versions prior to 3.2.13 SrbTransLatin WordPress plugin versions prior to 2.4.1
Description The issue arises from the use of a third-party library that removes escaping on some HTML characters, leading to a cross-site scripting vulnerability. This allows for potential malicious script injection and execution.
Recommendations For WP-Optimize WordPress plugin versions prior to 3.2.13, update to version 3.2.13 or later. For SrbTransLatin WordPress plugin versions prior to 2.4.1, update to version 2.4.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-1119

Affected Products

Srbtranslatin
Wp-Optimize