First published: Fri Oct 27 2023(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alkaweb Eonet Manual User Approve plugin <= 2.1.3 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xtendify Eonet Manual User Approve | <=2.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-32738 is medium with a severity value of 5.9.
Yes, WordPress Eonet Manual User Approve Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS).
The affected software is Xtendify Eonet Manual User Approve plugin versions up to and including 2.1.3 for WordPress.
To fix the XSS vulnerability in WordPress Eonet Manual User Approve Plugin <= 2.1.3, update to the latest version of the plugin.
The CWE of CVE-2023-32738 is CWE-79 (Improper Neutralization of Input During Web Page Generation).