CVE-2023-2711: Ultimate Product Catalog < 5.2.6 - Admin+ Stored XSS
The Ultimate Product Catalog WordPress plugin before 5.2.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-2711.
What is the severity level of CVE-2023-2711?
The severity level of CVE-2023-2711 is medium with a score of 4.8.
How does CVE-2023-2711 impact users?
CVE-2023-2711 allows high privilege users to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disallowed.
Which version of the Ultimate Product Catalog WordPress plugin is affected by CVE-2023-2711?
The Ultimate Product Catalog WordPress plugin before version 5.2.6 is affected by CVE-2023-2711.
Is there a fix available for CVE-2023-2711?
Yes, updating to version 5.2.6 of the Ultimate Product Catalog WordPress plugin will fix CVE-2023-2711.