CVE-2023-30482: WordPress WPBulky Plugin < 1.0.10 is vulnerable to Cross Site Scripting (XSS)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in VillaTheme WPBulky plugin <= 1.0.10 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-30482?
CVE-2023-30482 is a Stored Cross-Site Scripting (XSS) vulnerability in the VillaTheme WPBulky plugin, with versions up to and including 1.0.10, which can be exploited by authenticated contributors or higher.
How severe is CVE-2023-30482?
CVE-2023-30482 has a severity rating of medium with a CVSS score of 5.4, indicating a moderate level of risk.
What is the affected software for CVE-2023-30482?
The affected software for CVE-2023-30482 is the VillaTheme WPBulky plugin with versions up to and including 1.0.10.
How can I mitigate the vulnerability in CVE-2023-30482?
To mitigate CVE-2023-30482, users should update the VillaTheme WPBulky plugin to a version higher than 1.0.10.
What is the Common Weakness Enumeration (CWE) identifier for CVE-2023-30482?
The Common Weakness Enumeration (CWE) identifier for CVE-2023-30482 is CWE-79, which corresponds to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').