CVE-2023-51488: WordPress Crowdsignal Dashboard – Polls, Surveys & more Plugin <= 3.0.11 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue affects Crowdsignal Dashboard – Polls, Surveys & more: from n/a through 3.0.11.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-51488?
CVE-2023-51488 has a medium severity due to its reflected cross-site scripting nature which may compromise user data.
How do I fix CVE-2023-51488?
To fix CVE-2023-51488, update the Crowdsignal Dashboard – Polls, Surveys & more to version 3.0.12 or later where this issue is resolved.
What software is affected by CVE-2023-51488?
CVE-2023-51488 affects Automattic Crowdsignal Dashboard versions up to and including 3.0.11.
What type of vulnerability is CVE-2023-51488?
CVE-2023-51488 is classified as a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2023-51488 lead to data theft?
Yes, CVE-2023-51488 can potentially allow attackers to execute malicious scripts in the user's browser, leading to data theft.