First published: Tue Jun 04 2024(Updated: )
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Tips and Tricks HQ Stripe Payments allows Code Injection.This issue affects Stripe Payments: from n/a through 2.0.79.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stripe Payments | <=2.0.79 | |
WordPress Accept Stripe Payments | <=2.0.79 |
Update to 2.0.80 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48285 is classified as a Medium severity vulnerability due to its potential for code injection via improper neutralization of scripts.
To fix CVE-2023-48285, update Stripe Payments or Accept Stripe Payments plugins to versions above 2.0.79.
CVE-2023-48285 can be exploited through cross-site scripting (XSS) attacks that allow attackers to inject arbitrary scripts into web pages.
CVE-2023-48285 affects Stripe Payments and WordPress Accept Stripe Payments versions up to and including 2.0.79.
Users running the affected versions of Stripe Payments or Accept Stripe Payments are impacted by CVE-2023-48285.