First published: Thu Mar 30 2023(Updated: )
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Webdevocean Image Hover Effects For Wpbakery Page Builder | <5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-23681.
The title of the vulnerability is Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions.
The vulnerability is a Stored Cross-Site Scripting (XSS) vulnerability in Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin <= 4.0 versions, and it requires contributor+ level authentication to exploit.
The vulnerability affects Webdevocean Image Hover Effects For Wpbakery Page Builder plugin versions up to and exclusive of 5.0.
The severity of the vulnerability is medium, with a CVSS score of 5.4.
To fix the vulnerability, update the Labib Ahmed Image Hover Effects For WPBakery Page Builder plugin to version 4.0 or newer.
Yes, you can find additional information about the vulnerability at the following link: [https://patchstack.com/database/vulnerability/image-hover-effects-visual-composer-extension/wordpress-image-hover-effects-for-wpbakery-page-builder-plugin-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve](https://patchstack.com/database/vulnerability/image-hover-effects-visual-composer-extension/wordpress-image-hover-effects-for-wpbakery-page-builder-plugin-4-0-cross-site-scripting-xss-vulnerability?_s_id=cve)
The vulnerability is associated with CWE-79, which is the Cross-Site Scripting (XSS) vulnerability category.