CVE-2023-0421: Cloud Manager <= 1.0 - Reflected XSS
The Cloud Manager WordPress plugin through 1.0 does not sanitise and escape the query param ricerca before outputting it in an admin panel, allowing unauthenticated attackers to trick a logged in admin to trigger a XSS payload by clicking a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0421?
CVE-2023-0421 has been classified as a high severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2023-0421?
To fix CVE-2023-0421, update the Cloud Manager WordPress plugin to a version beyond 1.0 that addresses this vulnerability.
Who is affected by CVE-2023-0421?
Any WordPress site using the Cloud Manager plugin version 1.0 or lower is vulnerable to CVE-2023-0421.
What type of attack does CVE-2023-0421 facilitate?
CVE-2023-0421 facilitates Cross-Site Scripting (XSS) attacks through unescaped query parameters.
Is it safe to use the Cloud Manager plugin after CVE-2023-0421?
It is unsafe to use the Cloud Manager plugin version 1.0 or lower until the vulnerability CVE-2023-0421 is patched.