First published: Mon May 15 2023(Updated: )
The Help Desk WP WordPress plugin through 1.2.0 does not sanitise and escape some parameters, which could allow users with a role as low as Editor to perform Cross-Site Scripting attacks.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Help Desk Wp | <=1.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1019 is a vulnerability in the Help Desk WP WordPress plugin through version 1.2.0 that allows users with as low as Editor role to perform Cross-Site Scripting attacks.
CVE-2023-1019 has a severity rating of 5.4, which is considered medium.
The affected software by CVE-2023-1019 is the Help Desk WP WordPress plugin up to version 1.2.0.
An attacker can exploit CVE-2023-1019 by injecting malicious scripts into certain parameters of the Help Desk WP WordPress plugin.
Yes, a fix for CVE-2023-1019 is available and users of the Help Desk WP WordPress plugin should update to the latest version.