CVE-2023-46310: WordPress wpDiscuz plugin <= 7.6.10 - Content Injection vulnerability
Published Jun 4, 2024
·Updated
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpDiscuz allows Code Injection.This issue affects wpDiscuz: from n/a through 7.6.10.
Affected Software
3 affected components
gVectors Team wpDiscuz
WordPress wpDiscuz<=7.6.10
gVectors Wpdiscuz Wordpress<7.6.11
Remediation
Information
Update to 7.6.11 or a higher version.
Event History
Jun 4, 2024
CVE Published
via MITRE·09:19 AM
Data Sourced
via MITRE·09:19 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-46310?
CVE-2023-46310 is classified as a basic Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2023-46310?
To fix CVE-2023-46310, update wpDiscuz to version 7.6.11 or later.
3
What products are affected by CVE-2023-46310?
CVE-2023-46310 affects wpDiscuz versions from n/a up to 7.6.10.
4
What type of vulnerability is CVE-2023-46310?
CVE-2023-46310 is an example of improper neutralization of script-related HTML tags, allowing for code injection.
5
Can CVE-2023-46310 be exploited remotely?
Yes, CVE-2023-46310 can be exploited remotely through specially crafted inputs.