First published: Wed Oct 25 2023(Updated: )
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TechnoWich WP ULike – Most Advanced WordPress Marketing Toolkit plugin <= 4.6.8 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
TechnoWich WP ULike | <=4.6.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45640 is a Cross-Site Scripting (XSS) vulnerability in the TechnoWich WP ULike – Most Advanced WordPress Marketing Toolkit plugin.
The severity of CVE-2023-45640 is medium with a CVSS score of 5.4.
CVE-2023-45640 affects TechnoWich WP ULike – Most Advanced WordPress Marketing Toolkit plugin versions up to and including 4.6.8.
The CWE for CVE-2023-45640 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2023-45640, you should update TechnoWich WP ULike – Most Advanced WordPress Marketing Toolkit plugin to version 4.6.9 or higher.