CVE-2023-30487: WordPress LearnPress Export Import Plugin <= 4.0.2 is vulnerable to Cross Site Scripting (XSS)
Published May 18, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThimPress LearnPress Export Import plugin <= 4.0.2 versions.
Affected Software
1 affected component
thimpress Learnpress Wordpress<=4.0.2
Remediation
Information
Update to 4.0.3 or a higher version.
Event History
May 18, 2023
CVE Published
via MITRE·08:37 AM
Data Sourced
via MITRE·08:37 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-30487?
CVE-2023-30487 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in the ThimPress LearnPress Export Import plugin, with versions up to and including 4.0.2.
2
How severe is CVE-2023-30487?
CVE-2023-30487 has a severity keyword of 'high' and a severity value of 6.1 out of 10.
3
How does CVE-2023-30487 affect the ThimPress LearnPress Export Import plugin?
CVE-2023-30487 affects the ThimPress LearnPress Export Import plugin with versions up to and including 4.0.2.
4
What is the Common Weakness Enumeration (CWE) number associated with CVE-2023-30487?
The Common Weakness Enumeration (CWE) number associated with CVE-2023-30487 is CWE-79.
5
Is there a patch or fix available for CVE-2023-30487?
Yes, a patch or fix is available for CVE-2023-30487. Please refer to the reference link for more information.