CVE-2023-34008: WordPress WP ERP Plugin <= 1.12.3 is vulnerable to Cross Site Scripting (XSS)
Published Aug 30, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in weDevs WP ERP plugin <= 1.12.3 versions.
Affected Software
1 affected component
weDevs Wp Erp Wordpress<=1.12.3
Remediation
Information
Update to 1.12.4 or a higher version.
Event History
Aug 30, 2023
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-34008?
CVE-2023-34008 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in the weDevs WP ERP plugin version 1.12.3 and below.
2
How severe is CVE-2023-34008?
CVE-2023-34008 has a severity rating of 6.1 (High).
3
What is the affected software of CVE-2023-34008?
The affected software of CVE-2023-34008 is the weDevs WP ERP plugin version 1.12.3 and below.
4
How can I fix CVE-2023-34008?
To fix CVE-2023-34008, update the weDevs WP ERP plugin to a version higher than 1.12.3.
5
What is CWE-79?
CWE-79 refers to Improper Neutralization of Input During Web Page Generation (XSS).