CVE-2023-0162: CPO Companion <= 1.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0162?
CVE-2023-0162 is classified as a high severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2023-0162?
To fix CVE-2023-0162, update the CPO Companion plugin to version 1.0.5 or later.
Who is affected by CVE-2023-0162?
CVE-2023-0162 affects users of the CPO Companion plugin for WordPress versions up to and including 1.0.4.
What type of attack does CVE-2023-0162 facilitate?
CVE-2023-0162 facilitates stored cross-site scripting (XSS) attacks.
What causes the vulnerability in CVE-2023-0162?
CVE-2023-0162 is caused by insufficient input sanitization and output escaping in the CPO Companion plugin.