CVE-2023-3170: tagDiv Composer < 4.2 - Admin+ Stored XSS
The tagDiv Composer WordPress plugin before 4.2, used as a companion by the Newspaper and Newsmag themes from tagDiv, does not validate and escape some settings, which could allow users with Admin privileges to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3170?
CVE-2023-3170 is a vulnerability in the tagDiv Composer WordPress plugin before version 4.2, which is used as a companion by the Newspaper and Newsmag themes from tagDiv.
How severe is CVE-2023-3170?
CVE-2023-3170 has a severity rating of 4.8, indicating a medium level of severity.
How does CVE-2023-3170 affect software?
CVE-2023-3170 affects the tagDiv Composer WordPress plugin before version 4.2.
Are there any known references for CVE-2023-3170?
Yes, you can find more information about CVE-2023-3170 at this reference: https://wpscan.com/vulnerability/e95ff3c6-283b-4e5e-bea0-1f1375da08da
What is the CWE ID for CVE-2023-3170?
The CWE ID for CVE-2023-3170 is 79.