First published: Wed May 03 2023(Updated: )
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Metaphor Creations Ditty plugin <= 3.0.32 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Metaphor Creations Ditty | <3.0.33 |
Update to 3.0.33 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-23874 is a Stored Cross-Site Scripting (XSS) vulnerability in the Metaphor Creations Ditty plugin.
The severity of CVE-2023-23874 is medium with a CVSS score of 5.4.
Versions up to and excluding 3.0.33 of the Metaphor Creations Ditty plugin are affected by CVE-2023-23874.
To fix CVE-2023-23874, update your Metaphor Creations Ditty plugin to version 3.0.33 or higher.
The Common Weakness Enumeration (CWE) ID associated with CVE-2023-23874 is CWE-79.