CVE-2023-28664: XSS
Published Mar 22, 2023
·Updated
The Meta Data and Taxonomies Filter WordPress plugin, in versions < 1.3.1, is affected by a reflected cross-site scripting vulnerability in the 'taxname' parameter of the mdfgettaxoptionsinwidget action, which can only be triggered by an authenticated user.
Affected Software
1 affected component
Pluginus Wordpress Meta Data And Taxonomies Filter Wordpress<=1.3.1
Event History
Mar 22, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID is CVE-2023-28664.
2
What is the affected software?
The affected software is the Meta Data and Taxonomies Filter WordPress plugin in versions < 1.3.1.
3
What is the severity of CVE-2023-28664?
The severity of CVE-2023-28664 is medium.
4
How can the vulnerability be triggered?
The vulnerability can be triggered by an authenticated user through the 'tax_name' parameter of the mdf_get_tax_options_in_widget action.
5
Is there a fix available for this vulnerability?
Yes, updating the Meta Data and Taxonomies Filter WordPress plugin to version 1.3.1 or higher will fix this vulnerability.