CVE-2023-2122: Image Optimizer by 10web < 1.0.27 - Reflected Cross-Site Scripting
Published Aug 16, 2023
·Updated
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowdtabsactive parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.
Affected Software
1 affected component
10web Image Optimizer Wordpress<1.0.27
Event History
Aug 16, 2023
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-2122.
2
What is the affected software?
The affected software is the Image Optimizer by 10web WordPress plugin before version 1.0.27.
3
What is the severity of CVE-2023-2122?
The severity of CVE-2023-2122 is medium.
4
How does CVE-2023-2122 impact the plugin?
CVE-2023-2122 allows an attacker to perform a reflected Cross-Site Scripting (XSS) attack on the plugin admin panel.
5
How can I fix CVE-2023-2122?
To fix CVE-2023-2122, update the Image Optimizer by 10web WordPress plugin to version 1.0.27 or later.