CVE-2023-23681: WordPress Image Hover Effects For WPBakery Page Builder Plugin <= 4.0 is vulnerable to Cross Site Scripting (XSS)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23681.
What is the title of the vulnerability?
The title of the vulnerability is Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.
What is the description of the vulnerability?
The vulnerability is a Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions, and it requires contributor+ level authentication to exploit.
What software versions are affected by the vulnerability?
The vulnerability affects Webdevocean Image Hover Effects For Wpbakery Page Builder plugin versions up to and exclusive of 5.0.
What is the severity of the vulnerability?
The severity of the vulnerability is medium, with a CVSS score of 5.4.
How can I fix the vulnerability?
To fix the vulnerability, update the Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin to version 4.0 or newer.
Is there any additional reference for the vulnerability?
Yes, you can find additional information about the vulnerability at the following link: [https://patchstack.com/database/vulnerability/image-hover-effects-visual-composer-extension/wordpress-image-hover-effects-for-wpbakery-page-builder-plugin-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/image-hover-effects-visual-composer-extension/wordpress-image-hover-effects-for-wpbakery-page-builder-plugin-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve)
What is the Common Weakness Enumeration (CWE) ID associated with the vulnerability?
The vulnerability is associated with CWE-79, which is the Cross-Site Scripting (XSS) vulnerability category.