CVE-2023-41235: WordPress Everest News Pro Theme <= 1.1.7 is vulnerable to Cross Site Scripting (XSS)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Everest News Pro theme <= 1.1.7 versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-41235?
CVE-2023-41235 is an Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in the Everest Themes Everest News Pro theme version 1.1.7 and below.
How severe is CVE-2023-41235?
CVE-2023-41235 has a severity level of 6.1, which is considered high.
How does CVE-2023-41235 affect the Everest News Pro theme?
CVE-2023-41235 allows unauthenticated attackers to execute malicious scripts in a victim's browser through specially crafted URL parameters.
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-41235?
The Common Weakness Enumeration (CWE) ID for CVE-2023-41235 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
How can I fix CVE-2023-41235?
To fix CVE-2023-41235, update the Everest Themes Everest News Pro theme to version 1.1.8 or higher, which contains a patch for this vulnerability.