CVE-2023-2580: AI-Engine < 1.6.83 - Admin+ Stored XSS
The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example, in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2580?
CVE-2023-2580 has a high severity rating due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2023-2580?
To fix CVE-2023-2580, update the AI Engine WordPress plugin to version 1.6.83 or later.
Who is affected by CVE-2023-2580?
CVE-2023-2580 affects high-privilege users such as admin in installations of the AI Engine WordPress plugin before version 1.6.83.
What type of attack does CVE-2023-2580 allow?
CVE-2023-2580 allows for Stored Cross-Site Scripting attacks due to insufficient sanitization and escaping of settings.
Can CVE-2023-2580 be exploited in a multisite setup?
Yes, CVE-2023-2580 can be exploited in a multisite setup even if the unfiltered_html capability is disallowed.