CVE-2023-3936: Blog2Social < 7.2.1 - Reflected XSS
Published Aug 21, 2023
·Updated
The Blog2Social WordPress plugin before 7.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
Adenion Blog2social Wordpress<7.2.1
Event History
Aug 21, 2023
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the Blog2Social WordPress plugin?
The vulnerability ID for the Blog2Social WordPress plugin is CVE-2023-3936.
2
What is the severity of CVE-2023-3936?
The severity of CVE-2023-3936 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2023-3936?
The affected software for CVE-2023-3936 is the Blog2Social WordPress plugin version up to 7.2.1.
4
What is the risk of CVE-2023-3936?
CVE-2023-3936 poses a risk of Reflected Cross-Site Scripting (XSS) attacks.
5
How can I mitigate CVE-2023-3936?
To mitigate CVE-2023-3936, make sure to update the Blog2Social WordPress plugin to version 7.2.1 or newer.