CVE-2023-50905: WordPress WP Activity Log plugin <= 4.6.1 - Cross Site Scripting (XSS) vulnerability
Published Feb 29, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows DOM-Based XSS.This issue affects WP Activity Log: from n/a through <= 4.6.1.
Affected Software
3 affected components
Melapress WP Activity Log<=4.6.1
WordPress WP Activity Log Plugin<=4.6.1
Melapress Wp Activity Log Wordpress<4.6.2
Remediation
Information
Update to 4.6.2 or a higher version.
Event History
Feb 29, 2024
CVE Published
via MITRE·05:35 AM
Data Sourced
via MITRE·05:35 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-50905?
CVE-2023-50905 has a moderate severity level due to its potential for allowing stored Cross-site Scripting (XSS) attacks.
2
How do I fix CVE-2023-50905?
To fix CVE-2023-50905, update the Melapress WP Activity Log plugin to version 4.6.2 or later.
3
Which versions are affected by CVE-2023-50905?
CVE-2023-50905 affects versions of the WP Activity Log plugin from n/a to 4.6.1.
4
What type of vulnerability is CVE-2023-50905?
CVE-2023-50905 is classified as a Cross-site Scripting (XSS) vulnerability.
5
Who is impacted by CVE-2023-50905?
Users of the Melapress WP Activity Log plugin on affected versions are impacted by CVE-2023-50905.