CVE-2023-28490: WordPress Mortgage Calculator Estatik Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS)
Published Sep 27, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.
Affected Software
1 affected component
Estatik Estatik Mortgage Calculator Wordpress<=2.0.7
Event History
Sep 27, 2023
CVE Published
via MITRE·05:05 AM
Data Sourced
via MITRE·05:05 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28490?
The severity of CVE-2023-28490 is classified as high due to the potential for unauthenticated attackers to execute malicious scripts.
2
How do I fix CVE-2023-28490?
To fix CVE-2023-28490, update the Estatik Mortgage Calculator plugin to version 2.0.8 or later.
3
What type of vulnerability is CVE-2023-28490?
CVE-2023-28490 is categorized as an unauthenticated reflected cross-site scripting (XSS) vulnerability.
4
Which versions of the Estatik Mortgage Calculator are affected by CVE-2023-28490?
CVE-2023-28490 affects Estatik Mortgage Calculator plugin versions 2.0.7 and earlier.
5
Can CVE-2023-28490 be exploited without user authentication?
Yes, CVE-2023-28490 can be exploited by unauthenticated users, making it particularly dangerous.