CVE-2023-0231: ShopLentor < 2.5.4 - Contributor+ Stored XSS
Published Feb 21, 2023
·Updated
The ShopLentor WordPress plugin before 2.5.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
HasThemes Shoplentor Wordpress<2.5.4
Event History
Feb 21, 2023
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-0231.
2
What is the severity of CVE-2023-0231?
The severity of CVE-2023-0231 is medium with a severity value of 5.4.
3
What is the affected software?
The affected software is the ShopLentor WordPress plugin before version 2.5.4.
4
What is the potential impact of this vulnerability?
This vulnerability could allow users with the contributor role and above to perform Stored Cross-Site Scripting (XSS) attacks.
5
How can I fix CVE-2023-0231?
To fix CVE-2023-0231, upgrade to version 2.5.4 or later of the ShopLentor WordPress plugin.