CVE-2023-23977: WordPress Heateor Social Comments Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments plugin <= 1.6.1 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23977.
What is the title of the vulnerability?
The title of the vulnerability is 'Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments plugin <= 1.6.1 versions.'
What is the severity of CVE-2023-23977?
The severity of CVE-2023-23977 is medium with a severity value of 5.4.
How does CVE-2023-23977 affect the software?
CVE-2023-23977 affects the Team Heateor WordPress Social Comments Plugin for Vkontakte Comments and Disqus Comments plugin versions up to and including 1.6.1.
How can I fix CVE-2023-23977?
To fix CVE-2023-23977, users should update the Team Heateor WordPress Social Comments Plugin to version 1.6.2 or higher.