First published: Mon Sep 25 2023(Updated: )
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Xtemos WoodMart plugin <= 7.2.4 versions.
Credit: audit@patchstack.com audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xtemos WoodMart | <=7.2.4 |
Update to 7.2.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-41872 is an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability in the Xtemos WoodMart plugin, versions <= 7.2.4.
CVE-2023-41872 has a severity rating of 6.1 (High).
CVE-2023-41872 affects the Xtemos WoodMart plugin, versions <= 7.2.4, and can be exploited by unauthenticated attackers to execute arbitrary JavaScript code in a victim's browser.
Yes, a fix is available for CVE-2023-41872 in the form of an updated version of the Xtemos WoodMart plugin (version > 7.2.4) which addresses the vulnerability.
The Common Weakness Enumeration (CWE) for CVE-2023-41872 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').