CVE-2023-0097: Post Grid, Post Carousel, & List Category Posts < 2.4.19 - Contributor+ Stored XSS
The Post Grid, Post Carousel, & List Category Posts WordPress plugin before 2.4.19 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-0097.
What is the severity level of CVE-2023-0097?
CVE-2023-0097 has a severity level of medium with a CVSS score of 5.4.
Which software versions are affected by CVE-2023-0097?
The Post Grid, Post Carousel, & List Category Posts WordPress plugin versions prior to 2.4.19 are affected by CVE-2023-0097.
What can an attacker do with this vulnerability?
An attacker with the contributor role and above can perform Stored Cross-Site Scripting (XSS) attacks.
Is there a fix available for CVE-2023-0097?
Yes, updating the affected plugin to version 2.4.19 or later will fix the vulnerability.