CVE-2023-28751: WordPress Wp Ultimate Review Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS)
Published Jun 23, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.
Affected Software
1 affected component
Wpmet Wp Ultimate Review Wordpress<=2.0.3
Remediation
Information
Update to 2.1.0 or a higher version.
Event History
Jun 23, 2023
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-28751.
2
What is the severity of CVE-2023-28751?
The severity of CVE-2023-28751 is medium.
3
What is the affected software for CVE-2023-28751?
The affected software for CVE-2023-28751 is Wpmet Wp Ultimate Review plugin version up to and including 2.0.3.
4
What is the CWE (Common Weakness Enumeration) for CVE-2023-28751?
The CWE for CVE-2023-28751 is CWE-79.
5
How do I fix the vulnerability CVE-2023-28751?
To fix the vulnerability CVE-2023-28751, update the Wpmet Wp Ultimate Review plugin to a version higher than 2.0.3.