CVE-2023-41241: WordPress SureCart Plugin <= 2.5.0 is vulnerable to Cross Site Scripting (XSS)
Published Sep 27, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For Creating Fast Online Stores plugin <= 2.5.0 versions.
Affected Software
1 affected component
SureCart SureCart WordPress<=2.5.0
Remediation
Information
Update to 2.5.1 or a higher version.
Event History
Sep 27, 2023
CVE Published
via MITRE·12:32 PM
Data Sourced
via MITRE·12:32 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-41241.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For C…'
3
What is the affected software?
The affected software is SureCart WordPress Ecommerce For Creating Fast Online Stores plugin versions up to and including 2.5.0.
4
What is the severity of the vulnerability?
The severity of the vulnerability is medium with a severity value of 4.8.
5
Is there a fix available for this vulnerability?
Yes, a fix is available. Please refer to the provided reference for more information.