CVE-2023-0176: Giveaways and Contests by RafflePress < 1.11.3 - Contributor+ Stored XSS
The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0176?
CVE-2023-0176 has been classified with a medium severity due to its potential for unauthorized access and modifications.
How do I fix CVE-2023-0176?
To fix CVE-2023-0176, upgrade the RafflePress Giveaways and Contests plugin to version 1.11.3 or later.
Who is affected by CVE-2023-0176?
CVE-2023-0176 affects users with the contributor role and above on websites using the vulnerable version of the RafflePress plugin.
What vulnerability does CVE-2023-0176 exploit?
CVE-2023-0176 exploits the failure to properly validate and escape shortcode attributes within the RafflePress plugin.
What are the potential consequences of CVE-2023-0176?
The potential consequences of CVE-2023-0176 include unauthorized manipulation of content on pages or posts where the shortcode is used.