PT-2024-15119 · WordPress · Wordpress

Akbar Kustirama

·

Published

2024-02-05

·

Updated

2024-02-09

·

CVE-2023-6884

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress plugin versions up to, and including, 3.1
Description The plugin is vulnerable to Stored Cross-Site Scripting via its shortcode due to insufficient input sanitization and output escaping on the place id attribute. This allows authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages, which will execute when a user accesses an injected page.
Recommendations For versions up to, and including, 3.1, consider disabling the shortcode functionality until a patch is available to prevent exploitation. Restrict access to pages that use the vulnerable shortcode to minimize the risk of arbitrary web script injection. Avoid using the place id attribute in the shortcode until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-6884

Affected Products

Wordpress