CVE-2023-47853: WordPress myCred Plugin <= 2.6.1 is vulnerable to Cross Site Scripting (XSS)
Published Nov 30, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin allows Stored XSS.This issue affects myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin: from n/a through 2.6.1.
Affected Software
1 affected component
Wpexperts Mycred Wordpress<=2.6.1
Event History
Nov 30, 2023
CVE Published
via MITRE·04:49 PM
Data Sourced
via MITRE·04:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the WordPress myCred Plugin?
The vulnerability ID for the WordPress myCred Plugin is CVE-2023-47853.
2
What is the severity of CVE-2023-47853?
The severity of CVE-2023-47853 is medium, with a severity value of 6.5.
3
What does CVE-2023-47853 affect?
CVE-2023-47853 affects the myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin version up to and including 2.6.1.
4
What is the CWE ID of CVE-2023-47853?
The CWE ID of CVE-2023-47853 is CWE-79.
5
Is there a fix available for CVE-2023-47853?
Yes, a fix is available for CVE-2023-47853. Please refer to the provided reference for more information.