First published: Mon Jun 05 2023(Updated: )
The WP Multi Store Locator WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WP Multi Store Locator | <=2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-0152 is medium with a severity value of 5.4.
The vulnerability in the WP Multi Store Locator WordPress plugin is a Stored Cross-Site Scripting (XSS) attack.
The vulnerability allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
The affected version of the WP Multi Store Locator WordPress plugin is 2.4.
To fix the vulnerability, update the WP Multi Store Locator WordPress plugin to the latest version available.