CVE-2023-45747: WordPress WP Lightbox 2 Plugin <= 3.0.6.5 is vulnerable to Cross Site Scripting (XSS)
Published Oct 24, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Syed Balkhi WP Lightbox 2 plugin <= 3.0.6.5 versions.
Affected Software
1 affected component
Syedbalkhi Wp Lightbox 2 Wordpress<=3.0.6.5
Remediation
Information
Update to 3.0.6.6 or a higher version.
Event History
Oct 24, 2023
CVE Published
via MITRE·11:24 AM
Data Sourced
via MITRE·11:24 AM
RemedyDescriptionSeverityWeakness
Oct 25, 2023
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-45747?
CVE-2023-45747 is a stored Cross-Site Scripting (XSS) vulnerability in the Syed Balkhi WP Lightbox 2 plugin <= 3.0.6.5 versions.
2
What is the severity of CVE-2023-45747?
The severity of CVE-2023-45747 is medium, with a severity value of 4.8.
3
What software versions are affected by CVE-2023-45747?
CVE-2023-45747 affects Syed Balkhi WP Lightbox 2 plugin versions up to and including 3.0.6.5.
4
How can I fix CVE-2023-45747?
To fix CVE-2023-45747, update your Syed Balkhi WP Lightbox 2 plugin to a version higher than 3.0.6.5.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-45747?
The Common Weakness Enumeration (CWE) ID for CVE-2023-45747 is CWE-79.