CVE-2023-28792: WordPress Continuous Image Carousel With Lightbox Plugin <= 1.0.15 is vulnerable to Cross Site Scripting (XSS)
Published Apr 7, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Continuous Image Carousel With Lightbox plugin <= 1.0.15 versions.
Affected Software
1 affected component
I13websolution Continuous Image Carosel With Lightbox Wordpress<1.0.16
Remediation
Information
Update to 1.0.16 or a higher version.
Event History
Apr 7, 2023
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-28792.
2
What is the severity of CVE-2023-28792?
The severity of CVE-2023-28792 is high with a severity value of 6.1.
3
What is the affected software for CVE-2023-28792?
The affected software for CVE-2023-28792 is I Thirteen Web Solution Continuous Image Carousel With Lightbox plugin versions up to and including 1.0.15.
4
What is the CWE category for CVE-2023-28792?
The CWE category for CVE-2023-28792 is CWE-79 (Cross-Site Scripting).
5
How can I fix CVE-2023-28792?
To fix CVE-2023-28792, update the I Thirteen Web Solution Continuous Image Carousel With Lightbox plugin to version 1.0.16 or higher.