CVE-2023-41661: WordPress Smarty for WordPress Plugin <= 3.1.35 is vulnerable to Cross Site Scripting (XSS)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PressPage Entertainment Inc. Smarty for WordPress plugin <= 3.1.35 versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-41661?
CVE-2023-41661 is an authentication (admin+) stored Cross-Site Scripting (XSS) vulnerability in the PressPage Entertainment Inc. Smarty for WordPress plugin version 3.1.35 and below.
How severe is CVE-2023-41661?
CVE-2023-41661 has a severity rating of medium (4.8).
How does CVE-2023-41661 impact the PressPage Entertainment Inc. Smarty for WordPress plugin?
CVE-2023-41661 allows an authenticated admin or higher user to inject malicious scripts into the plugin, which can lead to unauthorized access or sensitive data theft.
How can I fix CVE-2023-41661?
To fix CVE-2023-41661, update the PressPage Entertainment Inc. Smarty for WordPress plugin to version 3.1.36 or higher, which contains a patch for the vulnerability.
What is the CWE classification of CVE-2023-41661?
CVE-2023-41661 is classified under CWE-79, which is the Cross-Site Scripting (XSS) vulnerability category.