CVE-2023-32962: WordPress WishSuite Plugin <= 1.3.4 is vulnerable to Cross Site Scripting (XSS)
Published Aug 30, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite – Wishlist for WooCommerce plugin <= 1.3.4 versions.
Affected Software
1 affected component
HasThemes Wishsuite Wordpress<=1.3.4
Remediation
Information
Update to 1.3.5 or a higher version.
Event History
Aug 30, 2023
CVE Published
via MITRE·11:56 AM
Data Sourced
via MITRE·11:56 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-32962.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in HasTheme WishSuite – Wishlist for …'
3
What is the affected software?
The affected software is HasTheme WishSuite – Wishlist for WooCommerce plugin version 1.3.4 and below.
4
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 4.8.
5
How can I fix the vulnerability?
To fix the vulnerability, update the HasTheme WishSuite – Wishlist for WooCommerce plugin to a version higher than 1.3.4.