CVE-2023-28171: WordPress Brilliance Theme <= 1.3.1 is vulnerable to Cross Site Scripting (XSS)
Published Jun 22, 2023
·Updated
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions.
Affected Software
1 affected component
WPChill Brilliance Wordpress<=1.3.1
Event History
Jun 22, 2023
CVE Published
via MITRE·08:01 AM
Data Sourced
via MITRE·08:01 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-28171?
CVE-2023-28171 is an Authentication (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in the WP Chill Brilliance theme version 1.3.1 and below.
2
What is the severity of CVE-2023-28171?
The severity of CVE-2023-28171 is medium with a CVSS score of 5.4.
3
How does CVE-2023-28171 affect the WP Chill Brilliance theme?
CVE-2023-28171 allows authenticated subscribers or higher to inject malicious scripts into the theme, which can be executed when other users view the affected pages.
4
How can I fix the CVE-2023-28171 vulnerability?
To fix the CVE-2023-28171 vulnerability, update the WP Chill Brilliance theme to version 1.3.2 or later.
5
What is CWE-79?
CWE-79 is a vulnerability category referred to as Cross-Site Scripting (XSS).