CVE-2023-23870: WordPress Responsive Vertical Icon Menu Plugin <= 1.5.8 is vulnerable to Cross Site Scripting (XSS)
Published Apr 4, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Responsive Vertical Icon Menu plugin <= 1.5.8 versions.
Affected Software
1 affected component
WpDevArt Responsive Vertical Icon Menu Wordpress<1.5.9
Remediation
Information
Update to 1.5.9 or a higher version.
Event History
Apr 4, 2023
CVE Published
via MITRE·12:44 PM
Data Sourced
via MITRE·12:44 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23870.
2
What is the title of the vulnerability?
The title of the vulnerability is Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in wpdevart Responsive Vertical Icon Menu plugin.
3
What is the affected software?
The affected software is the wpdevart Responsive Vertical Icon Menu plugin version 1.5.8 and below.
4
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 4.8.
5
How do I fix the vulnerability?
To fix the vulnerability, update the wpdevart Responsive Vertical Icon Menu plugin to version 1.5.9 or higher.