CVE-2023-23820: WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
Published May 3, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
Affected Software
1 affected component
properfraction Profilepress Wordpress<4.5.5
Remediation
Information
Update to 4.5.5 or a higher version.
Event History
May 3, 2023
CVE Published
via MITRE·12:39 PM
Data Sourced
via MITRE·12:39 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23820?
The severity of CVE-2023-23820 is medium with a severity value of 5.4.
2
What is the vulnerability description of CVE-2023-23820?
CVE-2023-23820 is an authentication (contributor+) stored Cross-Site Scripting (XSS) vulnerability found in ProfilePress Membership Team ProfilePress plugin versions <= 4.5.4.
3
Which software versions are affected by CVE-2023-23820?
ProfilePress Membership Team ProfilePress plugin versions up to and exclusive of 4.5.5 are affected by CVE-2023-23820.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-23820?
The Common Weakness Enumeration (CWE) ID for CVE-2023-23820 is 79.