CVE-2023-32580: WordPress Password Protected Plugin <= 2.6.2 is vulnerable to Cross Site Scripting (XSS)
Published Jun 23, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPExperts Password Protected plugin <= 2.6.2 versions.
Affected Software
1 affected component
Wpexperts Password Protected Wordpress<=2.6.2
Remediation
Information
Update to 2.6.3 or a higher version.
Event History
Jun 23, 2023
CVE Published
via MITRE·12:05 PM
Data Sourced
via MITRE·12:05 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-32580?
The severity of CVE-2023-32580 is medium, with a severity value of 4.8.
2
How does CVE-2023-32580 affect WPExperts Password Protected plugin?
CVE-2023-32580 affects WPExperts Password Protected plugin versions up to and including 2.6.2.
3
What is the vulnerability type of CVE-2023-32580?
CVE-2023-32580 is a Stored Cross-Site Scripting (XSS) vulnerability.
4
How can I fix the CVE-2023-32580 vulnerability?
To fix the CVE-2023-32580 vulnerability, update WPExperts Password Protected plugin to version 2.6.3 or newer.
5
Where can I find more information about CVE-2023-32580?
You can find more information about CVE-2023-32580 on Patchstack's vulnerability database.