CVE-2023-0375: Easy Affiliate Links < 3.7.1 - Contributor+ Stored XSS
Published Feb 21, 2023
·Updated
The Easy Affiliate Links WordPress plugin before 3.7.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Bootstrapped Easy Affiliate Links Wordpress<3.7.1
Event History
Feb 21, 2023
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of the Easy Affiliate Links WordPress plugin?
The vulnerability ID is CVE-2023-0375.
2
What is the severity of CVE-2023-0375?
The severity of CVE-2023-0375 is medium with a CVSS score of 5.4.
3
Which software is affected by CVE-2023-0375?
The Easy Affiliate Links WordPress plugin version up to 3.7.1 is affected.
4
What is the impact of CVE-2023-0375?
CVE-2023-0375 allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
5
How can I fix CVE-2023-0375?
Updating the Easy Affiliate Links WordPress plugin to version 3.7.1 or newer will fix CVE-2023-0375.