CVE-2023-0233: ActiveCampaign < 8.1.12 - Contributor+ Stored XSS
The ActiveCampaign WordPress plugin before 8.1.12 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0233?
CVE-2023-0233 has a medium severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2023-0233?
To resolve CVE-2023-0233, update the ActiveCampaign WordPress plugin to version 8.1.12 or later.
Who is affected by CVE-2023-0233?
CVE-2023-0233 affects users with the contributor role and above in the WordPress environment using the vulnerable ActiveCampaign plugin.
What type of vulnerability is CVE-2023-0233?
CVE-2023-0233 is a Stored Cross-Site Scripting (XSS) vulnerability.
What versions of ActiveCampaign are vulnerable to CVE-2023-0233?
ActiveCampaign WordPress plugin versions before 8.1.12 are vulnerable to CVE-2023-0233.