CVE-2023-1404: Weaver Show Posts <= 1.6 - Authenticated(Contributor+) Stored Cross-Site Scripting via Display Name
The Weaver Show Posts Plugin for WordPress is vulnerable to stored Cross-Site Scripting due to insufficient escaping of the profile display name in versions up to, and including, 1.6. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-1404.
What is the severity of CVE-2023-1404?
The severity of CVE-2023-1404 is medium.
How is the Weaver Show Posts Plugin for WordPress affected by the vulnerability?
The Weaver Show Posts Plugin for WordPress versions up to, and including, 1.6 is affected by this vulnerability.
Who can exploit the vulnerability?
Authenticated attackers with contributor-level and above permissions can exploit the vulnerability.
How can I fix the vulnerability in the Weaver Show Posts Plugin for WordPress?
Update your Weaver Show Posts Plugin for WordPress to a version that includes the necessary fixes.