CVE-2023-23668: WordPress GiveWP Plugin <= 2.25.1 is vulnerable to Cross Site Scripting (XSS)
Published May 8, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in GiveWP plugin <= 2.25.1 versions.
Affected Software
1 affected component
GiveWP GiveWP WordPress<2.25.2
Remediation
Information
Update to 2.25.2 or a higher version.
Event History
May 8, 2023
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
RemedyDescriptionSeverityWeakness
Data Sourced
12:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this XSS vulnerability is CVE-2023-23668.
2
What is the severity level of CVE-2023-23668?
CVE-2023-23668 has a severity level of medium.
3
What is the affected software for CVE-2023-23668?
The affected software for CVE-2023-23668 is the GiveWP plugin version 2.25.1 and below.
4
How can I fix the XSS vulnerability in GiveWP plugin?
To fix the XSS vulnerability in GiveWP plugin, you should upgrade to version 2.25.2 or later.
5
Is there any additional information about CVE-2023-23668?
Yes, you can find more information about CVE-2023-23668 at the following reference: [link](https://patchstack.com/database/vulnerability/give/wordpress-givewp-plugin-2-25-1-contributor-cross-site-scripting-xss-vulnerability?_s_id=cve)