CVE-2023-30877: WordPress XML for Google Merchant Center Plugin <= 3.0.1 is vulnerable to Cross Site Scripting (XSS)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3.0.1 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30877?
CVE-2023-30877 is classified as a reflected cross-site scripting (XSS) vulnerability, which can allow attackers to execute malicious scripts in a user's web browser.
How do I fix CVE-2023-30877?
To fix CVE-2023-30877, users should update the Maxim Glazunov XML for Google Merchant Center plugin to version 3.0.2 or later.
Which versions are affected by CVE-2023-30877?
CVE-2023-30877 affects the Maxim Glazunov XML for Google Merchant Center plugin versions up to and including 3.0.1.
What systems are impacted by CVE-2023-30877?
CVE-2023-30877 impacts WordPress installations using the Maxim Glazunov XML for Google Merchant Center plugin.
Is authentication required to exploit CVE-2023-30877?
No, CVE-2023-30877 is an unauthenticated reflected XSS vulnerability, allowing exploitation without user authentication.