CVE-2023-1805: Product Catalog Feed by PixelYourSite < 2.1.1 - Reflected XSS
Published May 2, 2023
·Updated
The Product Catalog Feed by PixelYourSite WordPress plugin before 2.1.1 does not sanitise and escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
PixelYourSite Product Catalog Feed Wordpress<2.1.1
Event History
May 2, 2023
CVE Published
via MITRE·07:04 AM
Data Sourced
via MITRE·07:04 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-1805?
CVE-2023-1805 has a medium severity rating due to its potential impact on high privilege users.
2
How do I fix CVE-2023-1805?
To fix CVE-2023-1805, update the PixelYourSite Product Catalog Feed plugin to version 2.1.1 or later.
3
Who is affected by CVE-2023-1805?
CVE-2023-1805 affects users of the PixelYourSite Product Catalog Feed plugin prior to version 2.1.1.
4
What type of vulnerability is CVE-2023-1805?
CVE-2023-1805 is a Reflected Cross-Site Scripting vulnerability.
5
What can attackers do with CVE-2023-1805?
Attackers can exploit CVE-2023-1805 to execute malicious scripts in the context of high privilege users.