First published: Fri Dec 29 2023(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget allows Stored XSS.This issue affects Back Button Widget: from n/a through 1.6.3.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpfactory | <=1.6.3 |
Update to 1.6.4 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51399 has a severity rating that indicates a high risk due to its potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2023-51399, upgrade the WPFactory Back Button Widget to version 1.6.4 or later.
Yes, CVE-2023-51399 affects all versions of the WPFactory Back Button Widget from the initial release up to version 1.6.3.
CVE-2023-51399 can enable attackers to execute stored XSS attacks, potentially compromising user data and session integrity.
Anyone using the WPFactory Back Button Widget versions up to 1.6.3 is affected by CVE-2023-51399.