CVE-2023-23898: WordPress Blocksy Companion Plugin <= 1.8.67 is vulnerable to Cross Site Scripting (XSS)
Published Apr 6, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in CreativeThemes Blocksy Companion plugin <= 1.8.67 versions.
Affected Software
1 affected component
creativethemes Blocksy Companion Wordpress<1.8.68
Remediation
Information
Update to 1.8.68 or a higher version.
Event History
Apr 6, 2023
CVE Published
via MITRE·10:08 AM
Data Sourced
via MITRE·10:08 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-23898?
CVE-2023-23898 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2023-23898?
To fix CVE-2023-23898, update the CreativeThemes Blocksy Companion plugin to version 1.8.68 or later.
3
Who is affected by CVE-2023-23898?
Users of the CreativeThemes Blocksy Companion plugin version 1.8.67 or earlier are affected by CVE-2023-23898.
4
What type of vulnerability is CVE-2023-23898?
CVE-2023-23898 is a stored cross-site scripting (XSS) vulnerability.
5
What versions of the Blocksy Companion plugin are vulnerable to CVE-2023-23898?
Versions of the Blocksy Companion plugin up to and including 1.8.67 are vulnerable to CVE-2023-23898.