CVE-2023-33309: WordPress Duplicator Pro Plugin <= 4.5.11 is vulnerable to Cross Site Scripting (XSS)
Published May 28, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Awesome Motive Duplicator Pro plugin <= 4.5.11 versions.
Affected Software
1 affected component
Awesomemotive Duplicator Wordpress<4.5.11.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Duplicator Pro plugin (Awesome Motive Duplicator Pro)to a version that resolves this vulnerability.Fixed in 4.5.11.1
Event History
May 28, 2023
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-33309?
The severity of CVE-2023-33309 is high with a CVSS score of 6.1.
2
What is the affected software for CVE-2023-33309?
The affected software for CVE-2023-33309 is Awesome Motive Duplicator Pro plugin versions up to 4.5.11.
3
How can I fix CVE-2023-33309?
To fix CVE-2023-33309, it is recommended to update the plugin to a version higher than 4.5.11.1.