CVE-2023-28931: WordPress Post Connector Plugin <= 1.0.9 is vulnerable to Cross Site Scripting (XSS)
Published Aug 8, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Never5 Post Connector plugin <= 1.0.9 versions.
Affected Software
1 affected component
Never5 Post Connector Wordpress<=1.0.9
Event History
Aug 8, 2023
CVE Published
via MITRE·12:35 PM
Data Sourced
via MITRE·12:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28931?
CVE-2023-28931 has a severity level of medium.
2
What is the affected software for CVE-2023-28931?
The affected software for CVE-2023-28931 is Never5 Post Connector plugin version up to and including 1.0.9.
3
What is the CWE number for CVE-2023-28931?
The CWE number for CVE-2023-28931 is 79.
4
How does CVE-2023-28931 impact admins?
CVE-2023-28931 can result in stored cross-site scripting (XSS) attacks, potentially allowing an attacker to execute malicious scripts in the admin's browser.
5
Is there a patch available for CVE-2023-28931?
Yes, a patch is available for CVE-2023-28931. Please refer to the following link for more information: [PATCH LINK]