CVE-2023-47185: WordPress wpDiscuz Plugin <= 7.6.11 is vulnerable to Cross Site Scripting (XSS)
Published Nov 6, 2023
·Updated
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team Comments — wpDiscuz plugin <= 7.6.11 versions.
Affected Software
1 affected component
gVectors Wpdiscuz Wordpress<=7.6.11
Remediation
Information
Update to 7.6.12 or a higher version.
Event History
Nov 6, 2023
CVE Published
via MITRE·10:56 AM
Data Sourced
via MITRE·10:56 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-47185?
CVE-2023-47185 is a vulnerability in the WordPress wpDiscuz plugin <= 7.6.11 that allows for cross-site scripting (XSS) attacks.
2
How severe is CVE-2023-47185?
CVE-2023-47185 has a severity rating of medium with a CVSS score of 6.1.
3
What is the affected software of CVE-2023-47185?
The affected software is the wpDiscuz plugin with versions up to and inclusive of 7.6.11.
4
What is the Common Weakness Enumeration (CWE) of CVE-2023-47185?
The CWE of CVE-2023-47185 is CWE-79, which is for cross-site scripting (XSS) vulnerabilities.
5
How can I fix CVE-2023-47185?
To fix CVE-2023-47185, update the wpDiscuz plugin to a version higher than 7.6.11.