CVE-2023-0059: Youzify < 1.2.2 - Contributor+ Stored XSS
Published Feb 21, 2023
·Updated
The Youzify WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
KaineLabs Youzify Wordpress<1.2.2
Event History
Feb 21, 2023
CVE Published
via MITRE·08:51 AM
Data Sourced
via MITRE·08:51 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-0059.
2
What is the severity of CVE-2023-0059?
The severity of CVE-2023-0059 is medium, with a severity value of 5.4.
3
What is the affected software for CVE-2023-0059?
The affected software for CVE-2023-0059 is the Youzify WordPress plugin before version 1.2.2.
4
What type of vulnerability is CVE-2023-0059?
CVE-2023-0059 is a Stored Cross-Site Scripting (XSS) vulnerability.
5
How can users mitigate the risk of CVE-2023-0059?
To mitigate the risk of CVE-2023-0059, users should update the Youzify WordPress plugin to version 1.2.2 or later.