CVE-2023-4500: Order Tracking Pro <= 3.3.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
The Order Tracking Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the order status parameter in versions up to, and including, 3.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers (admin or higher) to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This only affects multi-site installations and installations where unfilteredhtml has been disabled.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-4500?
CVE-2023-4500 is a vulnerability in the Order Tracking Pro plugin for WordPress that allows authenticated attackers to inject malicious scripts through the order status parameter.
What is the severity of CVE-2023-4500?
CVE-2023-4500 has a severity rating of medium (4.8).
How does CVE-2023-4500 affect the Order Tracking Pro plugin for WordPress?
CVE-2023-4500 affects versions up to and including 3.3.6 of the Order Tracking Pro plugin for WordPress.
How can authenticated attackers exploit CVE-2023-4500?
Authenticated attackers with admin or higher privileges can exploit CVE-2023-4500 by injecting malicious scripts through the order status parameter.
Are there any references to learn more about CVE-2023-4500?
Yes, you can learn more about CVE-2023-4500 by referring to the following links: [link1], [link2].