First published: Wed May 03 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Properfraction Profilepress | <4.5.5 | |
ProfilePress | <4.5.5 |
Update to 4.5.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-23830.
The severity of CVE-2023-23830 is high (6.1).
The affected software is ProfilePress Membership Team ProfilePress plugin versions up to 4.5.4.
The vulnerability can be exploited through unauthenticated reflected cross-site scripting (XSS).
Yes, a fix is available for CVE-2023-23830. Update to version 4.5.5 or later of the ProfilePress Membership Team ProfilePress plugin.