CVE-2023-23789: WordPress Premmerce Redirect Manager Plugin <= 1.0.9 is vulnerable to Cross Site Scripting (XSS)
Published May 10, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Premmerce Premmerce Redirect Manager plugin <= 1.0.9 versions.
Affected Software
1 affected component
Premmerce Premmerce Redirect Manager Wordpress<=1.0.9
Event History
May 10, 2023
CVE Published
via MITRE·07:28 AM
Data Sourced
via MITRE·07:28 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23789?
CVE-2023-23789 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2023-23789?
To fix CVE-2023-23789, update the Premmerce Redirect Manager plugin to version 1.0.10 or later.
3
Which versions are affected by CVE-2023-23789?
CVE-2023-23789 affects all versions of the Premmerce Redirect Manager plugin up to and including version 1.0.9.
4
What type of vulnerability is CVE-2023-23789?
CVE-2023-23789 is an authenticated stored cross-site scripting (XSS) vulnerability.
5
Who is at risk from CVE-2023-23789?
Websites using the Premmerce Redirect Manager plugin versions 1.0.9 or lower, especially those with admin+ user access, are at risk from CVE-2023-23789.