First published: Mon Feb 06 2023(Updated: )
The GamiPress WordPress plugin before 1.0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
GamiPress | <1.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-0154.
The severity of CVE-2023-0154 is medium.
The GamiPress WordPress plugin versions before 1.0.9 are affected by this vulnerability.
CVE-2023-0154 could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Updating to GamiPress WordPress plugin version 1.0.9 or later fixes the vulnerability.