First published: Wed Aug 30 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in weDevs WP ERP plugin <= 1.12.3 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
wedevs WP ERP WordPress | <=1.12.3 | |
weDevs WP ERP | <=1.12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34008 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the weDevs WP ERP plugin version 1.12.3 and below.
CVE-2023-34008 has a severity rating of 6.1 (High).
The affected software of CVE-2023-34008 is the weDevs WP ERP plugin version 1.12.3 and below.
To fix CVE-2023-34008, update the weDevs WP ERP plugin to a version higher than 1.12.3.
CWE-79 refers to Improper Neutralization of Input During Web Page Generation (XSS).