First published: Thu Aug 31 2023(Updated: )
The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers (admin or higher) to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Etoilewebdesign Order Tracking | <=3.3.6 | |
<=3.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4500 is a vulnerability in the Order Tracking Pro plugin for WordPress that allows authenticated attackers to inject malicious scripts through the order status parameter.
CVE-2023-4500 has a severity rating of medium (4.8).
CVE-2023-4500 affects versions up to and including 3.3.6 of the Order Tracking Pro plugin for WordPress.
Authenticated attackers with admin or higher privileges can exploit CVE-2023-4500 by injecting malicious scripts through the order status parameter.
Yes, you can learn more about CVE-2023-4500 by referring to the following links: [link1], [link2].