CVE-2023-25479: WordPress Podlove Subscribe button Plugin <= 1.3.7 is vulnerable to Cross Site Scripting (XSS)
Published Apr 25, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Podlove Podlove Subscribe button plugin <= 1.3.7 versions.
Affected Software
1 affected component
podlove Podlove Subscribe Button Wordpress<1.3.9
Remediation
Information
Update to 1.3.9 or a higher version.
Event History
Apr 25, 2023
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-25479?
CVE-2023-25479 is considered a medium severity vulnerability due to its potential for exploiting stored cross-site scripting.
2
How do I fix CVE-2023-25479?
To fix CVE-2023-25479, update the Podlove Subscribe Button plugin to version 1.3.9 or later.
3
What type of vulnerability is CVE-2023-25479?
CVE-2023-25479 is an authenticated stored cross-site scripting (XSS) vulnerability.
4
Which versions of the Podlove Subscribe Button plugin are affected by CVE-2023-25479?
CVE-2023-25479 affects versions of the Podlove Subscribe Button plugin up to and including 1.3.7.
5
Who is impacted by CVE-2023-25479?
Administrators and users of websites utilizing the affected versions of the Podlove Subscribe Button plugin may be impacted by CVE-2023-25479.