CVE-2023-0376: Qubely < 1.8.5 - Contributor+ Stored XSS
The Qubely WordPress plugin before 1.8.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0376?
CVE-2023-0376 is categorized as a medium-severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2023-0376?
To fix CVE-2023-0376, update the Qubely WordPress plugin to version 1.8.5 or later.
Who is affected by CVE-2023-0376?
CVE-2023-0376 affects users with contributor roles and above using versions of the Qubely plugin prior to 1.8.5.
What type of attack is associated with CVE-2023-0376?
CVE-2023-0376 is associated with Stored Cross-Site Scripting attacks, which can allow attackers to execute malicious scripts in the context of a user’s browser.
What specifically causes CVE-2023-0376?
CVE-2023-0376 is caused by the Qubely plugin failing to properly validate and escape block options before outputting them on a page or post.