CVE-2023-23830: WordPress ProfilePress Plugin <= 4.5.4 is vulnerable to Cross Site Scripting (XSS)
Published May 3, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
Affected Software
2 affected components
ProfilePress Profilepress Wordpress<4.5.5
properfraction Profilepress Wordpress<4.5.5
Remediation
Information
Update to 4.5.5 or a higher version.
Event History
May 3, 2023
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23830.
2
What is the severity of CVE-2023-23830?
The severity of CVE-2023-23830 is high (6.1).
3
What is the affected software?
The affected software is ProfilePress Membership Team ProfilePress plugin versions up to 4.5.4.
4
How can the vulnerability be exploited?
The vulnerability can be exploited through unauthenticated reflected cross-site scripting (XSS).
5
Is there a fix available for CVE-2023-23830?
Yes, a fix is available for CVE-2023-23830. Update to version 4.5.5 or later of the ProfilePress Membership Team ProfilePress plugin.