First published: Sun Apr 23 2023(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPChill CPO Content Types plugin <= 1.1.0 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpchill Cpo Content Types | <=1.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25451 is a stored Cross-Site Scripting (XSS) vulnerability in the WPChill CPO Content Types plugin version 1.1.0 and earlier.
CVE-2023-25451 has a severity rating of 4.8 out of 10, indicating a medium level of severity.
CVE-2023-25451 affects WPChill CPO Content Types plugin versions up to and including 1.1.0.
The CWE ID for CVE-2023-25451 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
To fix the CVE-2023-25451 vulnerability, update WPChill CPO Content Types plugin to version 1.1.1 or later, which contains a patch for the vulnerability.