CVE-2023-0175: Smart Logo Showcase Lite <= 1.1.9 - Contributor+ Stored XSS
The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-0175.
What is the severity of CVE-2023-0175?
The severity of CVE-2023-0175 is medium with a CVSS score of 5.4.
Which software is affected by CVE-2023-0175?
The Responsive Clients Logo Gallery Plugin for WordPress plugin versions 1.0.0 to 1.1.9 are affected by CVE-2023-0175.
How can users exploit CVE-2023-0175?
Users with the contributor role and above can exploit CVE-2023-0175 to perform Stored Cross-Site Scripting (XSS) attacks.
Is there a fix available for CVE-2023-0175?
Yes, updating to the latest version of the Responsive Clients Logo Gallery Plugin for WordPress (1.2.0 or higher) will fix CVE-2023-0175.