CVE-2023-25790: WordPress WoodMart theme <= 7.0.4 - Unauth Arbitrary Shortcodes Injection
Improper Authentication, Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in xtemos WoodMart allows Cross-Site Scripting (XSS).This issue affects WoodMart: from n/a through 7.0.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25790?
CVE-2023-25790 is classified as a high severity vulnerability due to its ability to enable cross-site scripting (XSS) attacks.
How do I fix CVE-2023-25790?
To fix CVE-2023-25790, update the WoodMart theme to version 7.0.5 or later as it contains the necessary security patches.
Which versions of WoodMart are affected by CVE-2023-25790?
CVE-2023-25790 affects all versions of WoodMart from n/a up to and including 7.0.4.
What is the impact of CVE-2023-25790 on users?
The impact of CVE-2023-25790 allows attackers to execute arbitrary JavaScript in the context of the user's session, potentially compromising user data.
Is there a way to mitigate the risk of CVE-2023-25790 before applying the fix?
To mitigate the risk of CVE-2023-25790, avoid using non-trusted sources for input and consider disabling certain functionalities of the theme until the update is applied.