CVE-2023-3650: Bubble Menu < 3.0.5 - Admin+ Stored XSS
The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example, in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Bubble Menu WordPress plugin vulnerability?
The vulnerability ID for the Bubble Menu WordPress plugin vulnerability is CVE-2023-3650.
What is the severity of CVE-2023-3650?
The severity of CVE-2023-3650 is medium with a severity value of 4.8.
What is the affected software for CVE-2023-3650?
The affected software for CVE-2023-3650 is the Bubble Menu WordPress plugin before version 3.0.5.
What type of vulnerability is CVE-2023-3650?
CVE-2023-3650 is a Stored Cross-Site Scripting (XSS) vulnerability.
How can the Bubble Menu WordPress plugin vulnerability be exploited?
The Bubble Menu WordPress plugin vulnerability can be exploited by high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.