CVE-2023-23972: WordPress Social Like Box and Page by WpDevArt Plugin <= 0.8.39 is vulnerable to Cross Site Scripting (XSS)
Published Apr 6, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions.
Affected Software
1 affected component
WpDevArt Social Like Box And Page Wordpress<=0.8.39
Remediation
Information
Update to 0.8.40 or a higher version.
Event History
Apr 6, 2023
CVE Published
via MITRE·05:50 AM
Data Sourced
via MITRE·05:50 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this XSS vulnerability is CVE-2023-23972.
2
What is the title of this vulnerability?
The title of this vulnerability is Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page…
3
What is the affected software for this XSS vulnerability?
The affected software for this XSS vulnerability is Wpdevart Social Like Box And Page plugin version up to and including 0.8.39.
4
What is the severity of this XSS vulnerability?
The severity of this XSS vulnerability is medium with a CVSS score of 4.8.
5
How can I fix this XSS vulnerability?
To fix this XSS vulnerability, update your Smplug-in Social Like Box and Page by WpDevArt plugin to a version higher than 0.8.39.