CVE-2023-28692: WordPress WP Abstracts Plugin <= 2.6.3 is vulnerable to Cross Site Scripting (XSS)
Published Aug 30, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Kevon Adonis WP Abstracts plugin <= 2.6.3 versions.
Affected Software
1 affected component
Kevonadonis Wp Abstracts Wordpress<=2.6.3
Event History
Aug 30, 2023
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28692?
CVE-2023-28692 has a medium severity rating due to its potential to allow authenticated users to execute malicious scripts.
2
How do I fix CVE-2023-28692?
To fix CVE-2023-28692, update the WP Abstracts plugin to version 2.6.4 or higher.
3
Who is affected by CVE-2023-28692?
Websites using the Kevon Adonis WP Abstracts plugin version 2.6.3 or earlier are vulnerable to CVE-2023-28692.
4
What kind of attack does CVE-2023-28692 facilitate?
CVE-2023-28692 facilitates stored Cross-Site Scripting (XSS) attacks that can affect users of the plugin.
5
Is authentication required to exploit CVE-2023-28692?
Yes, exploitation of CVE-2023-28692 requires authentication as it is an authenticated stored XSS vulnerability.