CVE-2023-28493: WordPress Newsmag Theme <= 2.4.4 is vulnerable to Cross Site Scripting (XSS)
Published May 8, 2023
·Updated
Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in Macho Themes NewsMag theme <= 2.4.4 versions.
Affected Software
1 affected component
Machothemes Newsmag Wordpress<=2.4.4
Event History
May 8, 2023
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
DescriptionSeverityWeakness
Data Sourced
03:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2023-28493?
CVE-2023-28493 is an Auth (subscriber+) Reflected Cross-Site Scripting (XSS) vulnerability in the Macho Themes NewsMag theme version 2.4.4 and below.
2
How severe is CVE-2023-28493?
CVE-2023-28493 has a severity value of 5.4, which is considered medium.
3
What is the affected software for CVE-2023-28493?
The affected software for CVE-2023-28493 is the Macho Themes NewsMag theme version 2.4.4 and below.
4
How can I fix CVE-2023-28493?
To fix CVE-2023-28493, upgrade your Macho Themes NewsMag theme to a version higher than 2.4.4.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-28493?
The CWE for CVE-2023-28493 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation.