CVE-2023-23876: WordPress wpDataTables Plugin <= 2.1.49 is vulnerable to Cross Site Scripting (XSS)
Published May 3, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TMS-Plugins wpDataTables plugin <= 2.1.49 versions.
Affected Software
1 affected component
Tms-outsource Wpdatatables Wordpress<2.1.50
Remediation
Information
Update to 2.1.50 or a higher version.
Event History
May 3, 2023
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-23876?
CVE-2023-23876 is an authentication bypass vulnerability that allows an attacker with contributor+ privileges to perform stored cross-site scripting attacks in TMS-Plugins wpDataTables plugin versions <= 2.1.49.
2
How severe is CVE-2023-23876?
CVE-2023-23876 has a severity score of 5.4 (Medium).
3
Which software versions are affected by CVE-2023-23876?
TMS-Plugins wpDataTables plugin versions up to 2.1.49 are affected by CVE-2023-23876.
4
How can I fix CVE-2023-23876?
To fix CVE-2023-23876, it is recommended to update TMS-Plugins wpDataTables plugin to version 2.1.50 or higher.
5
What is the CWE number associated with CVE-2023-23876?
CVE-2023-23876 is associated with CWE-79, which is the Common Weakness Enumeration identifier for cross-site scripting (XSS) vulnerabilities.