CVE-2023-32738: WordPress Eonet Manual User Approve Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS)
Published Oct 27, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Alkaweb Eonet Manual User Approve plugin <= 2.1.3 versions.
Affected Software
1 affected component
Xtendify Eonet Manual User Approve Wordpress<=2.1.3
Event History
Oct 27, 2023
CVE Published
08:16 PM
Data Sourced
08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-32738?
The severity of CVE-2023-32738 is medium with a severity value of 5.9.
2
Is WordPress Eonet Manual User Approve Plugin <= 2.1.3 vulnerable to Cross Site Scripting (XSS)?
Yes, WordPress Eonet Manual User Approve Plugin <= 2.1.3 is vulnerable to Cross Site Scripting (XSS).
3
What is the affected software of CVE-2023-32738?
The affected software is Xtendify Eonet Manual User Approve plugin versions up to and including 2.1.3 for WordPress.
4
How can I fix the XSS vulnerability in WordPress Eonet Manual User Approve Plugin <= 2.1.3?
To fix the XSS vulnerability in WordPress Eonet Manual User Approve Plugin <= 2.1.3, update to the latest version of the plugin.
5
What is the CWE of CVE-2023-32738?
The CWE of CVE-2023-32738 is CWE-79 (Improper Neutralization of Input During Web Page Generation).