CVE-2023-47517: WordPress SendPress Newsletters plugin <= 1.23.11.6 - Reflected Cross Site Scripting (XSS) vulnerability
Published Nov 14, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SendPress Newsletters sendpress allows DOM-Based XSS.This issue affects SendPress Newsletters: from n/a through <= 1.23.11.6.
Affected Software
1 affected component
Pressified Sendpress Wordpress<=1.23.11.6
Event History
Nov 14, 2023
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-47517.
2
What is the severity level of CVE-2023-47517?
The severity level of CVE-2023-47517 is high with a CVSS score of 7.1.
3
What is the affected software?
The affected software is the SendPress Newsletters plugin version 1.23.11.6 for WordPress.
4
What is the vulnerability description?
The vulnerability is an unauthenticated reflected Cross-Site Scripting (XSS) vulnerability in the SendPress Newsletters plugin version 1.23.11.6 for WordPress.
5
How do I fix the vulnerability?
To fix this vulnerability, update the SendPress Newsletters plugin to a version higher than 1.23.11.6.