CVE-2023-0367: Pricing Tables For WPBakery Page Builder < 3.0 - Contributor+ Stored XSS
The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) WordPress plugin before 3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0367?
CVE-2023-0367 has a medium severity rating due to its potential exploitation by unauthorized users.
How do I fix CVE-2023-0367?
To fix CVE-2023-0367, update the Pricing Tables for WPBakery Page Builder plugin to version 3.0 or later.
Who is affected by CVE-2023-0367?
Users of the Pricing Tables for WPBakery Page Builder plugin versions prior to 3.0 are affected by CVE-2023-0367.
What type of vulnerability is CVE-2023-0367?
CVE-2023-0367 is a cross-site scripting (XSS) vulnerability that allows users to inject malicious scripts.
What are the potential impacts of CVE-2023-0367?
The potential impacts of CVE-2023-0367 include unauthorized actions and data exposure for users with limited permissions.