First published: Mon Sep 25 2023(Updated: )
The Locatoraid Store Locator WordPress plugin before 3.9.24 does not sanitise and escape the lpr-search parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Plainware Locatoraid | <3.9.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4476 is a vulnerability in the Locatoraid Store Locator WordPress plugin before version 3.9.24 that allows for Reflected Cross-Site Scripting.
CVE-2023-4476 has a severity rating of medium (6.1) based on the Common Vulnerability Scoring System (CVSS).
CVE-2023-4476 affects the Plainware Locatoraid plugin versions before 3.9.24, allowing for Reflected Cross-Site Scripting attacks.
To fix CVE-2023-4476, update the Plainware Locatoraid plugin to version 3.9.24 or higher.
Reflected Cross-Site Scripting (XSS) is a type of security vulnerability that allows an attacker to inject malicious scripts into web pages viewed by other users.