CVE-2023-50376: WordPress Simple Membership Plugin <= 4.3.8 is vulnerable to Unauth. Reflected Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider Simple Membership allows Reflected XSS.This issue affects Simple Membership: from n/a through 4.3.8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50376?
CVE-2023-50376 has been classified as a high severity vulnerability due to its potential for reflected cross-site scripting (XSS) attacks.
How do I fix CVE-2023-50376?
To fix CVE-2023-50376, upgrade the Simple Membership plugin to version 4.3.9 or later.
Which versions of Simple Membership are affected by CVE-2023-50376?
CVE-2023-50376 affects all versions of the Simple Membership plugin from n/a through 4.3.8.
What type of vulnerability is CVE-2023-50376?
CVE-2023-50376 is identified as an improper neutralization of input during web page generation, leading to a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2023-50376 be exploited remotely?
Yes, CVE-2023-50376 can be exploited remotely by attackers to execute malicious scripts in a user's browser.