CVE-2023-2113: Autoptimize < 3.1.7 - Admin+ Stored Cross-Site Scripting via Settings Import
The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfilteredhtml capability is disabled, such as in a multisite setup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2113?
CVE-2023-2113 has a high severity rating due to its potential for exploitation by high privileged users.
How do I fix CVE-2023-2113?
To fix CVE-2023-2113, update the Autoptimize WordPress plugin to version 3.1.7 or later.
Who is affected by CVE-2023-2113?
CVE-2023-2113 affects users of the Autoptimize WordPress plugin version prior to 3.1.7.
What kind of attack is possible with CVE-2023-2113?
CVE-2023-2113 allows high privileged users to inject arbitrary JavaScript into the admin panel.
Is unfiltered_html capability relevant to CVE-2023-2113?
Yes, CVE-2023-2113 can be exploited even when the unfiltered_html capability is disabled for the user.