CVE-2023-24006: WordPress WP Terms Popup – Terms and Conditions and Privacy Policy WordPress Popups Plugin <= 2.6.0 is vulnerable to Cross Site Scripting (XSS)
Published Apr 6, 2023
·Updated
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Link Software LLC WP Terms Popup plugin <= 2.6.0 versions.
Affected Software
1 affected component
Linksoftwarellc Wp Terms Popup Wordpress<2.6.1
Remediation
Information
Update to 2.6.1 or a higher version.
Event History
Apr 6, 2023
CVE Published
via MITRE·07:55 AM
Data Sourced
via MITRE·07:55 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-24006?
CVE-2023-24006 is classified as a high severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2023-24006?
To fix CVE-2023-24006, update the WP Terms Popup plugin to version 2.6.1 or higher.
3
Who is affected by CVE-2023-24006?
CVE-2023-24006 affects users of the WP Terms Popup plugin versions 2.6.0 and earlier.
4
What type of vulnerability is CVE-2023-24006?
CVE-2023-24006 is an authenticated Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2023-24006 lead to unauthorized access?
Yes, CVE-2023-24006 could potentially allow an attacker to execute scripts in the context of a user's session.