CVE-2023-23650: WordPress MainWP Code Snippets Extension Plugin <= 4.0.2 is vulnerable to Cross Site Scripting (XSS)
Published Mar 23, 2023
·Updated
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in MainWP MainWP Code Snippets Extension plugin <= 4.0.2 versions.
Affected Software
1 affected component
MainWP Code Snippets Extension Wordpress<4.0.3
Remediation
Information
Update to 4.0.3 or a higher version.
Event History
Mar 23, 2023
CVE Published
via MITRE·12:40 PM
Data Sourced
via MITRE·12:40 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-23650.
2
What is the title of this vulnerability?
The title of this vulnerability is Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in MainWP MainWP Code Snippets E…
3
What is the severity of CVE-2023-23650?
The severity of CVE-2023-23650 is medium with a severity score of 5.4.
4
What software versions are affected by CVE-2023-23650?
MainWP Code Snippets Extension plugin versions up to (but not including) 4.0.3 are affected by CVE-2023-23650.
5
How can I fix the CVE-2023-23650 vulnerability?
To fix the CVE-2023-23650 vulnerability, update the MainWP Code Snippets Extension plugin to version 4.0.3 or higher.