CVE-2023-23710: WordPress WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23710.
What is the title of the vulnerability?
The title of the vulnerability is Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login ...
What is the severity of CVE-2023-23710?
The severity of CVE-2023-23710 is medium with a severity value of 4.8.
How does CVE-2023-23710 affect the software?
CVE-2023-23710 affects the miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin versions <= 7.5.14.
Is there a fix available for CVE-2023-23710?
Yes, a fix is available for CVE-2023-23710. It is recommended to update to version 7.6.0 or above of the miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin.