CVE-2023-0733: Newsletter Popup <= 1.2 - Unauthenticated Stored XSS
Published May 30, 2023
·Updated
The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks
Affected Software
1 affected component
Newsletter Popup Project Newsletter Popup Wordpress<=1.2
Event History
May 30, 2023
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionWeakness
Data Sourced
08:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-0733?
CVE-2023-0733 is classified as a medium severity vulnerability due to its potential for stored Cross-Site Scripting attacks.
2
How do I fix CVE-2023-0733?
To fix CVE-2023-0733, update the Newsletter Popup WordPress plugin to a version later than 1.2.
3
Who is affected by CVE-2023-0733?
Any user of the Newsletter Popup WordPress plugin version 1.2 or earlier is affected by CVE-2023-0733.
4
What type of attack is associated with CVE-2023-0733?
CVE-2023-0733 is associated with stored Cross-Site Scripting (XSS) attacks.
5
Can unauthenticated users exploit CVE-2023-0733?
Yes, unauthenticated users can exploit CVE-2023-0733 to execute stored XSS attacks.