CVE-2023-1473: Responsive WordPress Slideshows 3.29.0 - Reflected XSS
Published Apr 17, 2023
·Updated
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
MetaSlider Slider\, Gallery\, And Carousel Wordpress<3.29.1
Event History
Apr 17, 2023
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-1473?
CVE-2023-1473 has a medium severity rating due to its potential for Reflected Cross-Site Scripting against high privilege users.
2
How do I fix CVE-2023-1473?
To resolve CVE-2023-1473, update the MetaSlider WordPress plugin to version 3.29.1 or later.
3
Which versions of MetaSlider are affected by CVE-2023-1473?
MetaSlider versions prior to 3.29.1 are affected by CVE-2023-1473.
4
What type of vulnerability is CVE-2023-1473?
CVE-2023-1473 is a Reflected Cross-Site Scripting vulnerability.
5
Who is at risk with CVE-2023-1473?
High privilege users, such as administrators of the affected WordPress installations, are at risk with CVE-2023-1473.