CVE-2023-0276: Weaver Xtreme Theme Support < 6.2.7 - Contributor+ Stored XSS
The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0276?
The severity of CVE-2023-0276 is medium.
What is the affected software for CVE-2023-0276?
The affected software for CVE-2023-0276 is the Weaver Xtreme Theme Support WordPress plugin version up to 6.2.7.
What is the vulnerability type for CVE-2023-0276?
The vulnerability type for CVE-2023-0276 is Stored Cross-Site Scripting (XSS).
How does CVE-2023-0276 affect users?
CVE-2023-0276 could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Is there a fix available for CVE-2023-0276?
Yes, updating to version 6.2.7 of the Weaver Xtreme Theme Support WordPress plugin will fix CVE-2023-0276.