CVE-2023-38000: Auth. Stored Cross-Site Scripting (XSS) vulnerability in WordPress core and Gutenberg plugin via Navigation Links Block
Auth. Stored (contributor+) Cross-Site Scripting (XSS) vulnerability in WordPress core 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.1.3, from 6.0 through 6.0.5, from 5.9 through 5.9.7 and Gutenberg plugin <= 16.8.0 versions.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-38000.
What is the severity of CVE-2023-38000?
The severity of CVE-2023-38000 is medium with a severity value of 5.4.
Which versions of WordPress core and Gutenberg plugin are affected by CVE-2023-38000?
WordPress core versions 5.9 through 6.3.1 and Gutenberg plugin up to version 16.8.0 are affected by CVE-2023-38000.
What is the impact of CVE-2023-38000?
CVE-2023-38000 is a stored Cross-Site Scripting (XSS) vulnerability that allows attackers with contributor+ privileges to inject malicious scripts into web pages viewed by other users, potentially leading to unauthorized actions or theft of sensitive information.
How can I fix the CVE-2023-38000 vulnerability?
To fix the CVE-2023-38000 vulnerability, it is recommended to update to WordPress core version 6.3.2 or apply the necessary security patches provided by the WordPress team. Additionally, updating the Gutenberg plugin to the latest version is also recommended.