CVE-2023-26517: WordPress Dashboard Widgets Suite Plugin <= 3.2.1 is vulnerable to Cross Site Scripting (XSS)
Published May 6, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jeff Starr Dashboard Widgets Suite plugin <= 3.2.1 versions.
Affected Software
1 affected component
Plugin-planet Dashboard Widget Suite Wordpress<3.2.2
Remediation
Information
Update to 3.2.2 or a higher version.
Event History
May 6, 2023
CVE Published
via MITRE·06:59 AM
Data Sourced
via MITRE·06:59 AM
RemedyDescriptionSeverityWeakness
Data Sourced
07:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-26517?
CVE-2023-26517 is a stored Cross-Site Scripting (XSS) vulnerability in the Jeff Starr Dashboard Widgets Suite plugin version <= 3.2.1.
2
How severe is CVE-2023-26517?
CVE-2023-26517 has a severity level of medium with a score of 4.8.
3
Which software versions are affected by CVE-2023-26517?
The Jeff Starr Dashboard Widgets Suite plugin versions up to and including 3.2.1 are affected by CVE-2023-26517.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-26517?
The CWE for CVE-2023-26517 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
5
How can I fix CVE-2023-26517?
To fix CVE-2023-26517, update the Jeff Starr Dashboard Widgets Suite plugin to version 3.2.2 or later.