CVE-2023-0378: Greenshift < 5.0 - Contributor+ Stored XSS
Published Feb 21, 2023
·Updated
The Greenshift WordPress plugin before 5.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
2 affected components
Greenshiftwp Greenshift - Animation And Page Builder Blocks Wordpress<5.0
Wpsoul Greenshift Wordpress<5.0
Event History
Feb 21, 2023
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-0378.
2
What is the severity of CVE-2023-0378?
The severity of CVE-2023-0378 is medium (5.4).
3
What is the affected software for CVE-2023-0378?
The affected software for CVE-2023-0378 is the Greenshift WordPress plugin version up to exclusive 5.0.
4
What is the impact of CVE-2023-0378?
CVE-2023-0378 could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
5
Is there a fix available for CVE-2023-0378?
It is recommended to update the Greenshift WordPress plugin to version 5.0 or above to fix CVE-2023-0378.