CVE-2023-26530: WordPress Updraft Plugin <= 0.6.1 is vulnerable to Cross Site Scripting (XSS)
Published Aug 17, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Paul Kehrer Updraft plugin <= 0.6.1 versions.
Affected Software
1 affected component
updraftplus Updraft Wordpress<=0.6.1
Event History
Aug 17, 2023
CVE Published
via MITRE·10:41 AM
Data Sourced
via MITRE·10:41 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-26530?
CVE-2023-26530 is an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability in the Paul Kehrer Updraft plugin version 0.6.1 and below.
2
How severe is CVE-2023-26530?
CVE-2023-26530 has a severity level of high with a CVSS score of 6.1.
3
What software versions are affected by CVE-2023-26530?
The Updraft plugin versions up to and including 0.6.1 are affected by CVE-2023-26530.
4
How can I fix CVE-2023-26530?
To fix CVE-2023-26530, update the Paul Kehrer Updraft plugin to a version higher than 0.6.1.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-26530?
The Common Weakness Enumeration (CWE) for CVE-2023-26530 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').