CVE-2023-0071: WP Tabs < 2.1.17 - Contributor+ Stored XSS
The WP Tabs WordPress plugin before 2.1.17 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the WP Tabs WordPress plugin?
The vulnerability ID for the WP Tabs WordPress plugin is CVE-2023-0071.
What is the severity of the WP Tabs WordPress plugin vulnerability?
The severity of the WP Tabs WordPress plugin vulnerability is medium (5.4).
How does the WP Tabs WordPress plugin vulnerability occur?
The WP Tabs WordPress plugin vulnerability occurs because it does not validate and escape some of its shortcode attributes before outputting them back in a page/post.
Who can exploit the WP Tabs WordPress plugin vulnerability?
Users with the contributor role and above can exploit the WP Tabs WordPress plugin vulnerability.
How can I fix the WP Tabs WordPress plugin vulnerability?
To fix the WP Tabs WordPress plugin vulnerability, update to version 2.1.17 or newer.