PT-2023-25974 · WordPress · Activitypub
Ben Bidner
·
Published
2023-10-16
·
Updated
2023-10-18
·
CVE-2023-3746
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ActivityPub WordPress plugin version 1.0.0 and earlier
Description
The issue allows contributors and above roles to perform Stored Cross-Site Scripting attacks due to the plugin's failure to sanitize and escape some data from post content.
Recommendations
For ActivityPub WordPress plugin versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Activitypub