CVE-2023-32505: WordPress Easy Hide Login Plugin <= 1.0.7 is vulnerable to Cross Site Scripting (XSS)
Published Aug 23, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Arshid Easy Hide Login plugin <= 1.0.7 versions.
Affected Software
1 affected component
Ciphercoin Easy Hide Login Wordpress<=1.0.7
Remediation
Information
Update to 1.0.8 or a higher version.
Event History
Aug 23, 2023
CVE Published
via MITRE·02:22 PM
Data Sourced
via MITRE·02:22 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-32505.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Arshid Easy Hide Login plugin <= 1.0.7'.
3
What is the severity of CVE-2023-32505?
The severity of CVE-2023-32505 is medium, with a severity value of 4.8.
4
What software is affected by this vulnerability?
The Arshid Easy Hide Login plugin version <= 1.0.7 is affected by this vulnerability.
5
How can I fix CVE-2023-32505?
To fix CVE-2023-32505, it is recommended to update the Arshid Easy Hide Login plugin to a version higher than 1.0.7.