CVE-2023-1596: tagDiv Composer < 4.0 - Reflected Cross-site Scripting
Published May 15, 2023
·Updated
The tagDiv Composer WordPress plugin before 4.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
tagDiv Composer WordPress<4.0
Event History
May 15, 2023
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-1596.
2
What is the severity of CVE-2023-1596?
The severity of CVE-2023-1596 is medium (6.1).
3
Which software is affected by CVE-2023-1596?
The tagDiv Composer WordPress plugin versions up to 4.0 are affected.
4
What is the impact of CVE-2023-1596?
CVE-2023-1596 could be used to perform Reflected Cross-Site Scripting attacks against high privilege users such as admin.
5
How can you fix CVE-2023-1596?
To fix CVE-2023-1596, update the tagDiv Composer WordPress plugin to version 4.0 or higher.