First published: Tue Apr 25 2023(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin <= 7.5.14 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
miniOrange WordPress Social Login and Register | <7.6.0 |
Update to 7.6.0 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-23710.
The title of the vulnerability is Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in miniOrange WordPress Social Login ...
The severity of CVE-2023-23710 is medium with a severity value of 4.8.
CVE-2023-23710 affects the miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin versions <= 7.5.14.
Yes, a fix is available for CVE-2023-23710. It is recommended to update to version 7.6.0 or above of the miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin.