First published: Tue May 02 2023(Updated: )
The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Plainviewplugins Mycryptocheckout | <2.124 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-1546.
The severity of CVE-2023-1546 is medium with a CVSS score of 6.1.
The affected software is the MyCryptoCheckout WordPress plugin before version 2.124.
CVE-2023-1546 is a Reflected Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2023-1546, update the MyCryptoCheckout WordPress plugin to version 2.124 or later.