CVE-2023-30472: WordPress URL Shortener by MyThemeShop Plugin <= 1.0.17 is vulnerable to Cross Site Scripting (XSS)
Published Sep 27, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions.
Affected Software
1 affected component
MyThemeShop Url Shortener Wordpress<=1.0.17
Event History
Sep 27, 2023
CVE Published
via MITRE·10:42 AM
Data Sourced
via MITRE·10:42 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-30472?
CVE-2023-30472 is an unauthenticated reflected cross-site scripting (XSS) vulnerability in the MyThemeShop URL Shortener plugin by MyThemeShop, specifically versions 1.0.17 and below.
2
How severe is CVE-2023-30472?
CVE-2023-30472 has a severity rating of 6.1 (high).
3
How does CVE-2023-30472 affect MyThemeShop URL Shortener?
CVE-2023-30472 allows an attacker to execute malicious JavaScript code in a victim's browser by tricking them into clicking a specially crafted link.
4
Is there a fix available for CVE-2023-30472?
Yes, a fix for CVE-2023-30472 is available in version 1.0.18 of the MyThemeShop URL Shortener plugin.
5
What is the Common Weakness Enumeration (CWE) for CVE-2023-30472?
The CWE for CVE-2023-30472 is CWE-79 (Cross-Site Scripting).