CVE-2023-2654: Conditional Menus < 1.2.1 - Reflected XSS
The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2654?
The severity of CVE-2023-2654 is considered high, as it allows for Reflected Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2023-2654?
To fix CVE-2023-2654, you should update the Conditional Menus WordPress plugin to version 1.2.1 or later.
Who is affected by CVE-2023-2654?
CVE-2023-2654 affects high privilege users, such as admins, of websites using the Conditional Menus WordPress plugin prior to version 1.2.1.
What type of vulnerability is CVE-2023-2654?
CVE-2023-2654 is a Reflected Cross-Site Scripting (XSS) vulnerability due to improper escaping of parameters.
Which plugin is associated with CVE-2023-2654?
CVE-2023-2654 is associated with the Conditional Menus WordPress plugin.