CVE-2023-41128: WordPress WP Roadmap Plugin <= 1.0.8 is vulnerable to Cross Site Scripting (XSS)
Published Nov 30, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design WP Roadmap – Product Feedback Board allows Stored XSS.This issue affects WP Roadmap – Product Feedback Board: from n/a through 1.0.8.
Affected Software
1 affected component
Iqonic Wp Roadmap Wordpress<=1.0.8
Remediation
Information
Update to 1.0.9 or a higher version.
Event History
Nov 30, 2023
CVE Published
via MITRE·12:16 PM
Data Sourced
via MITRE·12:16 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-41128.
2
What is the severity of CVE-2023-41128?
The severity of CVE-2023-41128 is medium with a severity score of 5.9.
3
What is the affected software for CVE-2023-41128?
The affected software for CVE-2023-41128 is WP Roadmap Plugin version 1.0.8 and below.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
How can I fix the CVE-2023-41128 vulnerability?
To fix the CVE-2023-41128 vulnerability, you should update your WP Roadmap Plugin to a version higher than 1.0.8 or apply any patches or fixes provided by the plugin developer.