CVE-2023-45050: WordPress Jetpack Plugin <= 12.8-a.1 is vulnerable to Cross Site Scripting (XSS)
Published Nov 30, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic Jetpack – WP Security, Backup, Speed, & Growth allows Stored XSS.This issue affects Jetpack – WP Security, Backup, Speed, & Growth: from n/a through 12.8-a.1.
Affected Software
1 affected component
Automattic Jetpack Wordpress<=12.8-a.1
Remediation
Information
Update to 12.8-a.3 or a higher version.
Event History
Nov 30, 2023
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-45050.
2
What is the severity of CVE-2023-45050?
The severity of CVE-2023-45050 is medium with a CVSS score of 6.5.
3
What is the affected software for CVE-2023-45050?
The affected software for CVE-2023-45050 is the WordPress Jetpack Plugin up to version 12.8-a.1.
4
What is the CWE (Common Weakness Enumeration) for CVE-2023-45050?
The CWE for CVE-2023-45050 is CWE-79.
5
How to fix CVE-2023-45050?
To fix CVE-2023-45050, update the WordPress Jetpack Plugin to version 12.8-a.2 or later, as recommended by the vendor.