First published: Mon Feb 13 2023(Updated: )
The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpdevart Social Like Box And Page | <0.8.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-0177 is medium, with a severity value of 5.4.
The affected software of CVE-2023-0177 is the Social Like Box and Page by WpDevArt WordPress plugin before version 0.8.41.
The vulnerability type of CVE-2023-0177 is Stored Cross-Site Scripting (XSS).
Users with the contributor role and above can exploit CVE-2023-0177 by performing Stored Cross-Site Scripting attacks.
To fix CVE-2023-0177, update the Social Like Box and Page by WpDevArt WordPress plugin to version 0.8.41 or later.