CVE-2023-1166: USM Premium < 16.3 - Admin+ Stored XSS
Published Jun 27, 2023
·Updated
The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example, in multisite setup).
Affected Software
1 affected component
UltimatelySocial Usm Premium Wordpress<16.3
Event History
Jun 27, 2023
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-1166.
2
What is the severity level of CVE-2023-1166?
The severity level of CVE-2023-1166 is medium with a CVSS score of 4.8.
3
How does this vulnerability affect the USM-Premium WordPress plugin?
This vulnerability affects the USM-Premium WordPress plugin version up to 16.3.
4
What is the impact of CVE-2023-1166?
CVE-2023-1166 allows high-privilege users such as admin to perform Stored Cross-Site Scripting attacks.
5
Is there a fix for this vulnerability?
Yes, the fix for this vulnerability is to update the USM-Premium WordPress plugin to version 16.3 or higher.