CVE-2023-50831: WordPress CURCY Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme CURCY – Multi Currency for WooCommerce allows Stored XSS.This issue affects CURCY – Multi Currency for WooCommerce: from n/a through 2.2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50831?
The severity of CVE-2023-50831 is considered medium due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2023-50831?
To fix CVE-2023-50831, you should update the CURCY – Multi Currency for WooCommerce plugin to version 2.2.1 or later.
Which versions of CURCY – Multi Currency for WooCommerce are affected by CVE-2023-50831?
CVE-2023-50831 affects CURCY – Multi Currency for WooCommerce versions from n/a through 2.2.0.
What are the risks associated with CVE-2023-50831?
The risks associated with CVE-2023-50831 include potential data theft and unauthorized actions performed by malicious users through stored XSS attacks.
Is CVE-2023-50831 specific to any platforms?
Yes, CVE-2023-50831 specifically affects the CURCY – Multi Currency for WooCommerce plugin used within WordPress.