CVE-2023-23996: WordPress ProfilePress Plugin <= 4.5.3 is vulnerable to Cross Site Scripting (XSS)
Published Apr 6, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions.
Affected Software
1 affected component
properfraction Profilepress Wordpress<4.5.4
Remediation
Information
Update to 4.5.4 or a higher version.
Event History
Apr 6, 2023
CVE Published
via MITRE·07:46 AM
Data Sourced
via MITRE·07:46 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-23996.
2
What is the title of the vulnerability?
The title of the vulnerability is Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin.
3
What is the severity of CVE-2023-23996?
The severity of CVE-2023-23996 is medium with a severity value of 4.8.
4
Which software versions are affected by CVE-2023-23996?
The ProfilePress Membership Team ProfilePress plugin versions up to 4.5.3 are affected by CVE-2023-23996.
5
How can I fix the vulnerability in ProfilePress Membership Team ProfilePress plugin?
To fix the vulnerability, update the ProfilePress plugin to version 4.5.4 or higher.