CVE-2023-45832: WordPress WP GoToWebinar Plugin <= 14.45 is vulnerable to Cross Site Scripting (XSS)
Published Oct 24, 2023
·Updated
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson WP GoToWebinar plugin <= 14.45 versions.
Affected Software
1 affected component
Northernbeacheswebsites Wp Gotowebinar Wordpress<=14.45
Remediation
Information
Udpate to 14.46 or a higher version.
Event History
Oct 24, 2023
CVE Published
via MITRE·12:12 PM
Data Sourced
via MITRE·12:12 PM
RemedyDescriptionSeverityWeakness
Oct 25, 2023
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-45832?
CVE-2023-45832 is a Stored Cross-Site Scripting (XSS) vulnerability in the Martin Gibson WP GoToWebinar plugin version 14.45 and below, which can be exploited by authenticated administrators or higher.
2
How severe is CVE-2023-45832?
CVE-2023-45832 has a severity rating of 4.8 out of 10, which is considered medium.
3
What software versions are affected by CVE-2023-45832?
The Martin Gibson WP GoToWebinar plugin versions up to and including 14.45 are affected by CVE-2023-45832.
4
How can CVE-2023-45832 be fixed?
To fix CVE-2023-45832, it is recommended to update the Martin Gibson WP GoToWebinar plugin to a version higher than 14.45.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-45832?
The CWE ID for CVE-2023-45832 is 79.