CVE-2023-25713: WordPress Quick Paypal Payments Plugin <= 5.7.25 is vulnerable to Cross Site Scripting (XSS)
Published Apr 7, 2023
·Updated
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Fullworks Quick Paypal Payments plugin <= 5.7.25 versions.
Affected Software
1 affected component
Fullworksplugins Quick Paypal Payments Wordpress<5.7.26
Remediation
Information
Update to 5.7.26 or a higher version.
Event History
Apr 7, 2023
CVE Published
via MITRE·12:54 PM
Data Sourced
via MITRE·12:54 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-25713?
CVE-2023-25713 is an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the Fullworks Quick Paypal Payments plugin.
2
What is the severity of CVE-2023-25713?
The severity of CVE-2023-25713 is high with a score of 6.1.
3
Which software versions are affected by CVE-2023-25713?
Versions up to and excluding 5.7.26 of the Fullworks Quick Paypal Payments plugin are affected by CVE-2023-25713.
4
How can I fix CVE-2023-25713?
To fix CVE-2023-25713, update the Fullworks Quick Paypal Payments plugin to version 5.7.26 or higher.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-25713?
The Common Weakness Enumeration (CWE) for CVE-2023-25713 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').