CVE-2023-41847: WordPress Notice Bar Plugin <= 3.1.0 is vulnerable to Cross Site Scripting (XSS)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WEN Solutions Notice Bar plugin <= 3.1.0 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-41847?
CVE-2023-41847 is an authentication (contributor+) stored Cross-Site Scripting (XSS) vulnerability in the WEN Solutions Notice Bar plugin version 3.1.0 and below.
What is the severity of CVE-2023-41847?
The severity of CVE-2023-41847 is rated as medium with a CVSS score of 5.4.
How does CVE-2023-41847 affect the WEN Solutions Notice Bar plugin?
CVE-2023-41847 allows attackers with contributor+ authentication to cause the plugin to store malicious JavaScript code, which can be executed when a user views the affected page.
How can I fix CVE-2023-41847?
To fix CVE-2023-41847, update the WEN Solutions Notice Bar plugin to version 3.1.1 or later.
Is there more information available about CVE-2023-41847?
Yes, you can find more information about CVE-2023-41847 at the following link: [CVE-2023-41847](https://patchstack.com/database/vulnerability/notice-bar/wordpress-notice-bar-plugin-3-1-0-cross-site-scripting-xss-vulnerability?_s_id=cve)