CVE-2023-44990: WordPress WOLF Plugin <= 1.0.7.1 is vulnerable to Cross Site Scripting (XSS)
Published Oct 17, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in realmag777 WOLF – WordPress Posts Bulk Editor and Manager Professional plugin <= 1.0.7.1 versions.
Affected Software
1 affected component
Pluginus Wolf - Wordpress Posts Bulk Editor And Products Manager Professional Wordpress<1.0.7.2
Remediation
Information
Update to 1.0.7.2 or a higher version.
Event History
Oct 17, 2023
CVE Published
via MITRE·09:01 AM
Data Sourced
via MITRE·09:01 AM
RemedyDescriptionSeverityWeakness
Data Sourced
10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-44990?
The severity of CVE-2023-44990 is medium with a score of 5.9.
2
How does CVE-2023-44990 affect the realmag777 WOLF plugin?
CVE-2023-44990 is a stored Cross-Site Scripting (XSS) vulnerability that affects the realmag777 WOLF plugin versions <= 1.0.7.1.
3
How can the realmag777 WOLF plugin be affected by CVE-2023-44990?
CVE-2023-44990 can be exploited by authenticated administrators or users with higher privileges in the realmag777 WOLF plugin.
4
What is the Common Weakness Enumeration (CWE) for CVE-2023-44990?
The Common Weakness Enumeration (CWE) for CVE-2023-44990 is CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')).
5
How can I fix CVE-2023-44990 in the realmag777 WOLF plugin?
To fix CVE-2023-44990, it is recommended to update the realmag777 WOLF plugin to version 1.0.7.2 or higher.