PT-2023-21886 · WordPress · Meta Data/Taxonomies Filter

Joshua Martinelle

·

Published

2023-03-22

·

Updated

2023-03-28

·

CVE-2023-28664

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Meta Data and Taxonomies Filter WordPress plugin versions prior to 1.3.1
Description The issue is a reflected cross-site scripting vulnerability in the tax name parameter of the mdf get tax options in widget action. This can only be triggered by an authenticated user.
Recommendations For versions prior to 1.3.1, update to version 1.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the mdf get tax options in widget action to minimize the risk of exploitation. Avoid using the tax name parameter in the affected action until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-28664

Affected Products

Meta Data/Taxonomies Filter