CVE-2023-0173: WPFunnels < 2.6.9 - Contributor+ Stored XSS
The Drag & Drop Sales Funnel Builder for WordPress plugin before 2.6.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0173?
CVE-2023-0173 has a moderate severity level due to the potential for Stored Cross-Site Scripting (XSS) attacks.
Who is affected by CVE-2023-0173?
CVE-2023-0173 affects users with the contributor role and above in the Drag & Drop Sales Funnel Builder for WordPress plugin versions prior to 2.6.9.
How do I fix CVE-2023-0173?
To fix CVE-2023-0173, upgrade the Drag & Drop Sales Funnel Builder for WordPress plugin to version 2.6.9 or later.
What types of attacks can CVE-2023-0173 allow?
CVE-2023-0173 can allow attackers to perform Stored Cross-Site Scripting (XSS) attacks, potentially compromising site security.
What is the nature of the vulnerability in CVE-2023-0173?
CVE-2023-0173 is caused by the plugin failing to validate and escape shortcode attributes before outputting them in posts, which can be exploited for XSS.