CVE-2023-27922: XSS
Published May 23, 2023
·Updated
Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.
Affected Software
1 affected component
Thenewsletterplugin Newsletter Wordpress<7.6.9
Event History
May 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-27922?
CVE-2023-27922 is a cross-site scripting vulnerability in Newsletter versions prior to 7.6.9.
2
How severe is CVE-2023-27922?
CVE-2023-27922 has a severity rating of 6.1 (medium).
3
How can an attacker exploit CVE-2023-27922?
An attacker can exploit CVE-2023-27922 by injecting an arbitrary script through a cross-site scripting vulnerability in Newsletter versions prior to 7.6.9.
4
Which software versions are affected by CVE-2023-27922?
Newsletter versions prior to 7.6.9 are affected by CVE-2023-27922.
5
Is there a fix available for CVE-2023-27922?
Yes, upgrading to Newsletter version 7.6.9 or higher will fix CVE-2023-27922.