CVE-2023-45755: WordPress BuddyPress Global Search Plugin <= 1.2.1 is vulnerable to Cross Site Scripting (XSS)
Published Oct 24, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BuddyBoss BuddyPress Global Search plugin <= 1.2.1 versions.
Affected Software
1 affected component
Buddyboss Buddypress Global Search Wordpress<=1.2.1
Event History
Oct 24, 2023
CVE Published
via MITRE·11:34 AM
Data Sourced
via MITRE·11:34 AM
DescriptionSeverityWeakness
Oct 25, 2023
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-45755?
CVE-2023-45755 is an authorization (admin+) stored Cross-Site Scripting (XSS) vulnerability in the BuddyBoss BuddyPress Global Search plugin version 1.2.1 and below.
2
What is the severity of CVE-2023-45755?
CVE-2023-45755 has a severity rating of 4.8, which is considered medium.
3
How does CVE-2023-45755 affect BuddyBoss BuddyPress Global Search?
CVE-2023-45755 affects BuddyBoss BuddyPress Global Search plugin versions 1.2.1 and below.
4
What is Cross-Site Scripting (XSS)?
Cross-Site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
5
Is there a patch available for CVE-2023-45755?
Yes, a patch is available for CVE-2023-45755. Please refer to the official reference link for more information on obtaining the patch.