CVE-2023-48285: WordPress Accept Stripe Payments plugin <= 2.0.79 - Content Injection vulnerability
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-48285?
CVE-2023-48285 is classified as a Medium severity vulnerability due to its potential for code injection via improper neutralization of scripts.
How do I fix CVE-2023-48285?
To fix CVE-2023-48285, update Stripe Payments or Accept Stripe Payments plugins to versions above 2.0.79.
What types of attacks can exploit CVE-2023-48285?
CVE-2023-48285 can be exploited through cross-site scripting (XSS) attacks that allow attackers to inject arbitrary scripts into web pages.
Which versions are affected by CVE-2023-48285?
CVE-2023-48285 affects Stripe Payments and WordPress Accept Stripe Payments versions up to and including 2.0.79.
Who is impacted by CVE-2023-48285?
Users running the affected versions of Stripe Payments or Accept Stripe Payments are impacted by CVE-2023-48285.