CVE-2023-30489: WordPress Email Subscription Popup Plugin <= 1.2.16 is vulnerable to Cross Site Scripting (XSS)
Published Aug 14, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions.
Affected Software
1 affected component
I13websolution Email Subscription Popup Wordpress<=1.2.16
Remediation
Information
Update to 1.2.17 or a higher version.
Event History
Aug 14, 2023
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-30489?
CVE-2023-30489 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in the I Thirteen Web Solution Email Subscription Popup plugin with version <= 1.2.16 for WordPress.
2
How severe is CVE-2023-30489?
CVE-2023-30489 has a severity rating of 6.1 (High).
3
What is the affected software of CVE-2023-30489?
The affected software of CVE-2023-30489 is the I Thirteen Web Solution Email Subscription Popup plugin with version <= 1.2.16 for WordPress.
4
What is the Common Weakness Enumeration (CWE) ID of CVE-2023-30489?
The Common Weakness Enumeration (CWE) ID of CVE-2023-30489 is 79.
5
How can I fix CVE-2023-30489?
To fix CVE-2023-30489, update the I Thirteen Web Solution Email Subscription Popup plugin to a version higher than 1.2.16.