CVE-2023-50879: WordPress WordPress.com Editing Toolkit Plugin <= 3.78784 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WordPress.Com Editing Toolkit allows Stored XSS.This issue affects WordPress.Com Editing Toolkit: from n/a through 3.78784.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50879?
CVE-2023-50879 has been rated as a high severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2023-50879?
To fix CVE-2023-50879, update the Automattic WordPress.Com Editing Toolkit to version 3.78785 or later.
What types of attacks can exploit CVE-2023-50879?
CVE-2023-50879 can be exploited to perform stored cross-site scripting attacks, allowing attackers to execute malicious scripts in user browsers.
Who is affected by CVE-2023-50879?
CVE-2023-50879 affects users of the Automattic WordPress.Com Editing Toolkit versions up to and including 3.78784.
Is there a specific patch for CVE-2023-50879?
Yes, the patch for CVE-2023-50879 is included in the update to version 3.78785 of the Automattic WordPress.Com Editing Toolkit.