CVE-2023-49743: WordPress Dashboard Widgets Suite Plugin <= 3.4.1 is vulnerable to Cross Site Scripting (XSS)
Published Dec 14, 2023
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Dashboard Widgets Suite allows Stored XSS.This issue affects Dashboard Widgets Suite: from n/a through 3.4.1.
Affected Software
1 affected component
Plugin-planet Dashboard Widget Suite Wordpress<3.4.2
Remediation
Information
Update to 3.4.2 or a higher version.
Event History
Dec 14, 2023
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-49743?
CVE-2023-49743 has a high severity due to the potential for stored cross-site scripting (XSS) attacks.
2
How do I fix CVE-2023-49743?
To fix CVE-2023-49743, upgrade Dashboard Widgets Suite to version 3.4.2 or later.
3
What types of attacks are possible with CVE-2023-49743?
CVE-2023-49743 allows for stored XSS attacks, which can compromise user sessions and sensitive information.
4
Which versions of Dashboard Widgets Suite are affected by CVE-2023-49743?
CVE-2023-49743 affects Dashboard Widgets Suite versions up to and including 3.4.1.
5
Is my website at risk if I am using an affected version of Dashboard Widgets Suite with CVE-2023-49743?
Yes, if you are using an affected version of Dashboard Widgets Suite, your website is at risk of exploitation via stored XSS.