CVE-2023-0362: Themify Portfolio Post < 1.2.2 - Contributor+ Stored XSS
Themify Portfolio Post WordPress plugin before 1.2.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0362?
CVE-2023-0362 has been classified with a high severity due to its potential for Stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2023-0362?
To mitigate CVE-2023-0362, update the Themify Portfolio Post plugin to version 1.2.2 or later.
What types of systems are affected by CVE-2023-0362?
CVE-2023-0362 affects the Themify Portfolio Post WordPress plugin versions prior to 1.2.2.
Which user roles can exploit CVE-2023-0362?
Users with the contributor role and above can exploit CVE-2023-0362 by embedding affected shortcodes.
What is the nature of the vulnerability in CVE-2023-0362?
CVE-2023-0362 involves a failure to validate and escape shortcode attributes, allowing for XSS attacks.