CVE-2023-27452: WordPress Button Generator – easily Button Builder Plugin <= 2.3.3 is vulnerable to Cross Site Scripting (XSS)
Published Jun 22, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wow-Company Button Generator – easily Button Builder plugin <= 2.3.3 versions.
Affected Software
1 affected component
Wow-estore Button Generator - Easily Button Builder Wordpress<=2.3.3
Remediation
Information
Update to 2.3.4 or a higher version.
Event History
Jun 22, 2023
CVE Published
via MITRE·11:59 AM
Data Sourced
via MITRE·11:59 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-27452?
CVE-2023-27452 has a medium severity rating due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2023-27452?
To mitigate CVE-2023-27452, update the Wow-Company Button Generator plugin to version 2.3.4 or later.
3
What types of attacks can CVE-2023-27452 facilitate?
CVE-2023-27452 can facilitate stored cross-site scripting attacks that may lead to data theft or session hijacking.
4
Which versions of the Button Generator plugin are affected by CVE-2023-27452?
CVE-2023-27452 affects all versions of the Wow-Company Button Generator plugin up to and including version 2.3.3.
5
Is user authentication required to exploit CVE-2023-27452?
Yes, CVE-2023-27452 requires admin-level authentication to exploit the stored cross-site scripting vulnerability.