CVE-2023-3182: Membership Plugin - Restrict Content < 3.2.3 - Reflected XSS
The Membership WordPress plugin before 3.2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Membership pluginto a version that resolves this vulnerability.Fixed in 3.2.3
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-3182.
What is the severity of CVE-2023-3182?
The severity of CVE-2023-3182 is medium.
What is the affected software of CVE-2023-3182?
The affected software of CVE-2023-3182 is the Membership WordPress plugin version up to exclusive 3.2.3.
What is the impact of CVE-2023-3182?
CVE-2023-3182 allows for Reflected Cross-Site Scripting attacks that could be used against high privilege users, such as admin.
How can I fix CVE-2023-3182?
To fix CVE-2023-3182, update to version 3.2.3 or later of the Membership WordPress plugin.