CVE-2023-23881: WordPress Circles Gallery Plugin <= 1.0.10 is vulnerable to Cross Site Scripting (XSS)
Published May 3, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GreenTreeLabs Circles Gallery plugin <= 1.0.10 versions.
Affected Software
1 affected component
GreenTreeLabs Circles Gallery Wordpress<=1.0.10
Event History
May 3, 2023
CVE Published
via MITRE·03:03 PM
Data Sourced
via MITRE·03:03 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23881?
CVE-2023-23881 has been classified as a high severity vulnerability due to its potential impact on affected systems.
2
How do I fix CVE-2023-23881?
To fix CVE-2023-23881, update the GreenTreeLabs Circles Gallery plugin to version 1.0.11 or later.
3
Who is affected by CVE-2023-23881?
CVE-2023-23881 affects users of the GreenTreeLabs Circles Gallery plugin version 1.0.10 and earlier on WordPress sites.
4
What type of vulnerability is CVE-2023-23881?
CVE-2023-23881 is a stored Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2023-23881 lead to data theft?
Yes, CVE-2023-23881 can potentially allow attackers to steal sensitive information by executing malicious scripts in the context of an affected user.