CVE-2023-0380: Easy Digital Downloads < 3.1.0.5 - Contributor+ Stored XSS
Published Feb 21, 2023
·Updated
The Easy Digital Downloads WordPress plugin before 3.1.0.5 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Sandhillsdev Easy Digital Downloads Wordpress<3.1.0.5
Event History
Feb 21, 2023
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-0380.
2
What is the severity level of CVE-2023-0380?
The severity level of CVE-2023-0380 is medium.
3
Which software is affected by CVE-2023-0380?
The Easy Digital Downloads WordPress plugin before version 3.1.0.5 is affected by CVE-2023-0380.
4
What is the consequence of CVE-2023-0380?
CVE-2023-0380 could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
5
How can I fix CVE-2023-0380?
Updating to version 3.1.0.5 or higher of the Easy Digital Downloads WordPress plugin will fix CVE-2023-0380.