First published: Thu Oct 26 2023(Updated: )
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=1.1.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46081 is a vulnerability in WordPress Lava Directory Manager Plugin <= 1.1.34 that allows for Cross-Site Scripting (XSS) attacks.
CVE-2023-46081 has a severity rating of 7.1, which is considered high.
The affected software is Lava Directory Manager Plugin version 1.1.34 and earlier.
CVE-2023-46081 is associated with CWE-79, which is Cross-Site Scripting (XSS).
To fix CVE-2023-46081, update your Lava Directory Manager Plugin to version 1.1.35 or later.