First published: Thu Nov 30 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold - Responsive Multi-Purpose Theme allows Reflected XSS.This issue affects Enfold - Responsive Multi-Purpose Theme: from n/a through 5.6.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kriesi Enfold | <=5.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38400 is high with a CVSS score of 7.1.
CVE-2023-38400 is a Cross-Site Scripting (XSS) vulnerability in the Kriesi Enfold - Responsive Multi-Purpose Theme.
The Kriesi Enfold - Responsive Multi-Purpose Theme versions up to and including 5.6.4 are affected by CVE-2023-38400.
The Cross-Site Scripting vulnerability in WordPress Enfold Theme can be exploited through reflected XSS.
Yes, a patch is available for CVE-2023-38400. More information can be found at the provided reference link.