CVE-2023-23670: WordPress Fancy Comments WordPress Plugin <= 1.2.10 is vulnerable to Cross Site Scripting (XSS)
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Team Heateor Fancy Comments WordPress plugin <= 1.2.10 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-23670?
CVE-2023-23670 is a Cross-Site Scripting (XSS) vulnerability in the Team Heateor Fancy Comments WordPress plugin version <= 1.2.10, allowing authenticated contributors or higher to execute malicious scripts on a victim's browser.
How severe is CVE-2023-23670?
CVE-2023-23670 has a severity rating of medium, with a CVSS score of 5.4.
What software is affected by CVE-2023-23670?
The Team Heateor Fancy Comments WordPress plugin version <= 1.2.10 is affected by CVE-2023-23670.
How can I fix CVE-2023-23670?
To fix CVE-2023-23670, update the Team Heateor Fancy Comments WordPress plugin to version 1.2.11 or higher.
What is the Common Weakness Enumeration (CWE) for CVE-2023-23670?
The Common Weakness Enumeration (CWE) for CVE-2023-23670 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').