CVE-2023-30473: WordPress YML for Yandex Market Plugin <= 3.10.7 is vulnerable to Cross Site Scripting (XSS)
Published Aug 16, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov YML for Yandex Market plugin <= 3.10.7 versions.
Affected Software
1 affected component
Icopydoc Yml For Yandex Market Wordpress<=3.10.7
Remediation
Information
Update to 3.10.8 or a higher version.
Event History
Aug 16, 2023
CVE Published
via MITRE·09:52 AM
Data Sourced
via MITRE·09:52 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-30473?
CVE-2023-30473 is classified as a high-severity reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2023-30473?
To fix CVE-2023-30473, update the YML for Yandex Market plugin to version 3.10.8 or later.
3
What versions are affected by CVE-2023-30473?
CVE-2023-30473 affects YML for Yandex Market plugin versions up to and including 3.10.7.
4
What is a reflected cross-site scripting (XSS) vulnerability?
A reflected cross-site scripting (XSS) vulnerability allows an attacker to inject malicious scripts into web pages viewed by other users.
5
Who is affected by CVE-2023-30473?
Users of the YML for Yandex Market plugin versions 3.10.7 or lower on WordPress sites are affected by CVE-2023-30473.