CVE-2023-51399: WordPress Back Button Widget Plugin <= 1.6.3 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Back Button Widget allows Stored XSS.This issue affects Back Button Widget: from n/a through 1.6.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51399?
CVE-2023-51399 has a severity rating that indicates a high risk due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2023-51399?
To fix CVE-2023-51399, upgrade the WPFactory Back Button Widget to version 1.6.4 or later.
Does CVE-2023-51399 affect other versions of the Back Button Widget?
Yes, CVE-2023-51399 affects all versions of the WPFactory Back Button Widget from the initial release up to version 1.6.3.
What types of attacks can CVE-2023-51399 enable?
CVE-2023-51399 can enable attackers to execute stored XSS attacks, potentially compromising user data and session integrity.
Who is affected by CVE-2023-51399?
Anyone using the WPFactory Back Button Widget versions up to 1.6.3 is affected by CVE-2023-51399.