CVE-2023-29100: WordPress The7 Theme <= 11.6.0 is vulnerable to Cross Site Scripting (XSS)
Published Jun 23, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dream-Theme The7 plugin <= 11.6.0 versions.
Affected Software
1 affected component
Dream-Theme The7 Wordpress<=11.6.0
Remediation
Information
Update to 11.6.1 or a higher version.
Event History
Jun 23, 2023
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-29100?
The severity of CVE-2023-29100 is high.
2
What is the description of CVE-2023-29100?
CVE-2023-29100 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the Dream-Theme The7 plugin.
3
Which versions of the Dream-Theme The7 plugin are affected by CVE-2023-29100?
CVE-2023-29100 affects versions up to and including 11.6.0 of the Dream-Theme The7 plugin.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-29100?
The Common Weakness Enumeration (CWE) ID for CVE-2023-29100 is CWE-79.
5
How can I fix CVE-2023-29100 in the Dream-Theme The7 plugin?
To fix CVE-2023-29100, update your Dream-Theme The7 plugin to a version higher than 11.6.0.