CVE-2023-24398: WordPress EZP Coming Soon Page Plugin <= 1.0.7.3 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Snap Creek Software EZP Coming Soon Page plugin <= 1.0.7.3 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-24398?
CVE-2023-24398 is an authentication (admin+) stored Cross-Site Scripting (XSS) vulnerability in the Snap Creek Software EZP Coming Soon Page plugin version <= 1.0.7.3.
What software is affected by CVE-2023-24398?
The Snap Creek Software EZP Coming Soon Page plugin version <= 1.0.7.3 is affected by CVE-2023-24398.
How severe is CVE-2023-24398?
CVE-2023-24398 is classified as a medium severity vulnerability with a severity value of 4.8.
How can I fix CVE-2023-24398?
To fix CVE-2023-24398, update the Snap Creek Software EZP Coming Soon Page plugin to a version higher than 1.0.7.3.
What is the Common Weakness Enumeration (CWE) for CVE-2023-24398?
The Common Weakness Enumeration (CWE) for CVE-2023-24398 is CWE-79, which is a category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').