CVE-2023-25451: WordPress CPO Content Types Plugin <= 1.1.0 is vulnerable to Cross Site Scripting (XSS)
Published Apr 23, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.
Affected Software
1 affected component
WPChill Cpo Content Types Wordpress<=1.1.0
Event History
Apr 23, 2023
CVE Published
via MITRE·10:41 AM
Data Sourced
via MITRE·10:41 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-25451?
CVE-2023-25451 is a stored Cross-Site Scripting (XSS) vulnerability in the WPChill CPO Content Types plugin version 1.1.0 and earlier.
2
How severe is CVE-2023-25451?
CVE-2023-25451 has a severity rating of 4.8 out of 10, indicating a medium level of severity.
3
Which software versions are affected by CVE-2023-25451?
CVE-2023-25451 affects WPChill CPO Content Types plugin versions up to and including 1.1.0.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-25451?
The CWE ID for CVE-2023-25451 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
5
How can I fix the CVE-2023-25451 vulnerability?
To fix the CVE-2023-25451 vulnerability, update WPChill CPO Content Types plugin to version 1.1.1 or later, which contains a patch for the vulnerability.