CVE-2023-23685: WordPress Portfolio – WordPress Portfolio Plugin Plugin <= 2.8.10 is vulnerable to Cross Site Scripting (XSS)
Published Apr 4, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in RadiusTheme Portfolio – WordPress Portfolio plugin <= 2.8.10 versions.
Affected Software
1 affected component
RadiusTheme Portfolio Wordpress<2.8.11
Remediation
Information
Update to 2.8.11 or a higher version.
Event History
Apr 4, 2023
CVE Published
via MITRE·11:05 AM
Data Sourced
via MITRE·11:05 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-23685?
CVE-2023-23685 is an authentication (contributor+) stored Cross-Site Scripting (XSS) vulnerability in the RadiusTheme Portfolio WordPress plugin.
2
What software versions are affected by CVE-2023-23685?
CVE-2023-23685 affects the RadiusTheme Portfolio WordPress plugin versions up to and including 2.8.10.
3
How severe is CVE-2023-23685?
CVE-2023-23685 has a severity score of 5.4, which is considered medium.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-23685?
The CWE for CVE-2023-23685 is CWE-79, which is for Cross-Site Scripting (XSS) vulnerabilities.
5
How can I fix CVE-2023-23685?
To fix CVE-2023-23685, update the RadiusTheme Portfolio WordPress plugin to version 2.8.11 or newer.