First published: Wed Sep 27 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MyThemeShop URL Shortener by MyThemeShop plugin <= 1.0.17 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mythemeshop Url Shortener | <=1.0.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30472 is an unauthenticated reflected cross-site scripting (XSS) vulnerability in the MyThemeShop URL Shortener plugin by MyThemeShop, specifically versions 1.0.17 and below.
CVE-2023-30472 has a severity rating of 6.1 (high).
CVE-2023-30472 allows an attacker to execute malicious JavaScript code in a victim's browser by tricking them into clicking a specially crafted link.
Yes, a fix for CVE-2023-30472 is available in version 1.0.18 of the MyThemeShop URL Shortener plugin.
The CWE for CVE-2023-30472 is CWE-79 (Cross-Site Scripting).