First published: Tue Oct 24 2023(Updated: )
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in BuddyBoss BuddyPress Global Search plugin <= 1.2.1 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Buddyboss Buddyboss Platform WordPress | <=1.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45755 is an authorization (admin+) stored Cross-Site Scripting (XSS) vulnerability in the BuddyBoss BuddyPress Global Search plugin version 1.2.1 and below.
CVE-2023-45755 has a severity rating of 4.8, which is considered medium.
CVE-2023-45755 affects BuddyBoss BuddyPress Global Search plugin versions 1.2.1 and below.
Cross-Site Scripting (XSS) is a type of security vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users.
Yes, a patch is available for CVE-2023-45755. Please refer to the official reference link for more information on obtaining the patch.