First published: Mon Mar 06 2023(Updated: )
The Download Attachments WordPress plugin before 1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dfactory Download Attachments | <1.2.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0076 has been classified as a medium severity vulnerability.
To fix CVE-2023-0076, update the Download Attachments plugin to version 1.3 or later.
Users with roles of contributor and above in WordPress installations using the affected plugin are at risk from CVE-2023-0076.
CVE-2023-0076 is a Stored Cross-Site Scripting (XSS) vulnerability.
Download Attachments plugin versions prior to 1.3 are vulnerable to CVE-2023-0076.