CVE-2023-0892: BizLibrary <= 1.1 - Admin+ Stored XSS
The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the BizLibrary WordPress plugin vulnerability?
The vulnerability ID for the BizLibrary WordPress plugin vulnerability is CVE-2023-0892.
What is the severity of CVE-2023-0892?
The severity of CVE-2023-0892 is medium with a severity value of 4.8.
What is the impact of the BizLibrary WordPress plugin vulnerability?
The vulnerability allows high privilege users to perform Stored Cross-Site Scripting (XSS) attacks.
How can high privilege users exploit the BizLibrary WordPress plugin vulnerability?
High privilege users such as admin can exploit the vulnerability by performing Stored Cross-Site Scripting (XSS) attacks.
Is there a fix available for the BizLibrary WordPress plugin vulnerability?
Currently, there is no information available about a fix for the BizLibrary WordPress plugin vulnerability. It is recommended to follow the provided reference for any updates or patches.