CVE-2023-4798: User Avatar - Reloaded < 1.2.2 - Contributor+ Stored XSS
Published Oct 16, 2023
·Updated
The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.
Affected Software
1 affected component
wpexperts User Avatar-reloaded Wordpress<1.2.2
Event History
Oct 16, 2023
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionWeakness
Data Sourced
08:15 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the User Avatar WordPress plugin?
The vulnerability ID for the User Avatar WordPress plugin is CVE-2023-4798.
2
What is the severity rating of CVE-2023-4798?
The severity rating for CVE-2023-4798 is medium (5.4).
3
What is the impact of CVE-2023-4798?
CVE-2023-4798 could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.
4
How does CVE-2023-4798 affect the User Avatar WordPress plugin?
CVE-2023-4798 affects the User Avatar WordPress plugin before version 1.2.2.
5
Is there a fix available for CVE-2023-4798?
Yes, updating the User Avatar WordPress plugin to version 1.2.2 or later will fix the vulnerability.