CVE-2023-3169: tagDiv Composer < 4.2 - Unauthenticated Stored XSS
Published Sep 11, 2023
·Updated
The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not have authorisation in a REST route and does not validate as well as escape some parameters when outputting them back, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
tagDiv tagDiv Composer WordPress<4.2
Event History
Sep 11, 2023
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-3169.
2
What is the severity of CVE-2023-3169?
The severity of CVE-2023-3169 is medium (6.1).
3
Which software is affected by CVE-2023-3169?
The TagDiv Composer WordPress plugin before version 4.2 is affected by CVE-2023-3169.
4
What is the impact of CVE-2023-3169?
CVE-2023-3169 could allow unauthenticated users to perform stored cross-site scripting (XSS) attacks.
5
Is there a fix available for CVE-2023-3169?
Yes, updating the TagDiv Composer WordPress plugin to version 4.2 or above will fix CVE-2023-3169.