CVE-2023-50828: WordPress Ultimate Dashboard Plugin <= 3.7.11 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Vongries Ultimate Dashboard – Custom WordPress Dashboard allows Stored XSS.This issue affects Ultimate Dashboard – Custom WordPress Dashboard: from n/a through 3.7.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50828?
CVE-2023-50828 is classified as a critical severity vulnerability due to its potential for stored Cross-site Scripting (XSS) attacks.
How do I fix CVE-2023-50828?
To mitigate CVE-2023-50828, update the Ultimate Dashboard plugin to version 3.7.12 or later.
What impact does CVE-2023-50828 have on users?
CVE-2023-50828 can allow attackers to execute malicious scripts in the context of users' browsers, compromising user data and integrity.
Which versions of Ultimate Dashboard are affected by CVE-2023-50828?
CVE-2023-50828 affects Ultimate Dashboard versions up to and including 3.7.11.
Is CVE-2023-50828 specific to WordPress?
Yes, CVE-2023-50828 specifically affects the Ultimate Dashboard plugin for WordPress.