CVE-2023-36689: WordPress WPFactory Helper Plugin <= 1.5.2 is vulnerable to Cross Site Scripting (XSS)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory WPFactory Helper plugin <= 1.5.2 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-36689?
CVE-2023-36689 is an Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability found in the WPFactory WPFactory Helper plugin version 1.5.2 and earlier.
What is the severity of CVE-2023-36689?
CVE-2023-36689 has a severity level of high with a CVSS score of 6.1.
How does CVE-2023-36689 affect the WPFactory WPFactory Helper plugin?
CVE-2023-36689 allows unauthenticated attackers to inject malicious JavaScript code into a website using the WPFactory WPFactory Helper plugin version 1.5.2 and earlier.
How can I fix CVE-2023-36689?
To fix CVE-2023-36689, upgrade WPFactory WPFactory Helper plugin to version 1.5.3 or later, which includes a patch for the vulnerability.
Where can I find more information about CVE-2023-36689?
You can find more information about CVE-2023-36689 and the patch in the WPCodeFactory vulnerability database at the following link: [https://patchstack.com/database/vulnerability/wpcodefactory-helper/wordpress-wpfactory-helper-plugin-1-5-2-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve]