CVE-2023-23891: WordPress Ocean Extra Plugin <= 2.1.1 is vulnerable to Cross Site Scripting (XSS)
Published Apr 6, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.1 versions. Needs the OceanWP theme installed and activated.
Affected Software
1 affected component
Oceanwp Ocean Extra WordPress<2.1.2
Remediation
Information
Update to 2.1.2 or a higher version.
Event History
Apr 6, 2023
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-23891?
CVE-2023-23891 is a Stored Cross-Site Scripting (XSS) vulnerability in the OceanWP Ocean Extra plugin.
2
What is the severity of CVE-2023-23891?
The severity of CVE-2023-23891 is medium with a severity value of 5.4.
3
How does CVE-2023-23891 affect the OceanWP Ocean Extra plugin?
CVE-2023-23891 affects OceanWP Ocean Extra plugin versions up to and including 2.1.1.
4
How can I fix CVE-2023-23891?
To fix CVE-2023-23891, you should update the OceanWP Ocean Extra plugin to version 2.1.2 or above.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-23891?
The Common Weakness Enumeration (CWE) ID for CVE-2023-23891 is CWE-79.