CVE-2023-39988: WordPress WxSync Plugin <= 2.7.23 is vulnerable to Cross Site Scripting (XSS)
Published Sep 4, 2023
·Updated
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ???(std.Cloud) WxSync plugin <= 2.7.23 versions.
Other sources
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 标准云(std.Cloud) WxSync plugin <= 2.7.23 versions.
— MITRE
Affected Software
1 affected component
Tencent Wxsync Wordpress<=2.7.23
Event History
Sep 4, 2023
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-39988.
2
What is the title of the vulnerability?
The title of the vulnerability is Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ???(std.Cloud) WxSync plugin...
3
What is the affected software?
The affected software is Tencent Wxsync plugin <= 2.7.23 versions.
4
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a CVSS score of 5.4.
5
How can I fix this vulnerability?
To fix this vulnerability, update the Tencent Wxsync plugin to version 2.7.24 or higher.