CVE-2023-0423: WordPress Amazon S3 Plugin < 1.6 - Reflected XSS
Published Apr 10, 2023
·Updated
The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
Wordpress Amazon S3 Project Wordpress Amazon S3 Wordpress<1.6
Event History
Apr 10, 2023
CVE Published
via MITRE·01:18 PM
Data Sourced
via MITRE·01:18 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-0423?
CVE-2023-0423 is considered a high severity vulnerability due to the potential impact on high privilege users like admins.
2
How do I fix CVE-2023-0423?
To fix CVE-2023-0423, update the WordPress Amazon S3 plugin to version 1.6 or later.
3
What vulnerabilities does CVE-2023-0423 introduce?
CVE-2023-0423 introduces a Reflected Cross-Site Scripting vulnerability that can be exploited by an attacker.
4
Who is affected by CVE-2023-0423?
CVE-2023-0423 affects users of the WordPress Amazon S3 Plugin prior to version 1.6.
5
Can CVE-2023-0423 lead to data breaches?
Yes, CVE-2023-0423 can potentially lead to unauthorized access and data breaches for high privilege users.