First published: Thu Feb 01 2024(Updated: )
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 Easy Video Player allows Stored XSS.This issue affects Easy Video Player: from n/a through 1.2.2.10.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Noorsplugin Easy Video Player | <=1.2.2.10 |
Update to 1.2.2.11 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-51689 is classified as a medium severity vulnerability due to its potential for Stored Cross-site Scripting (XSS) attacks.
To fix CVE-2023-51689, upgrade Easy Video Player to a version higher than 1.2.2.10.
CVE-2023-51689 affects the Easy Video Player plugin for WordPress versions up to and including 1.2.2.10.
CVE-2023-51689 is an improper neutralization of input during web page generation, leading to a stored cross-site scripting (XSS) vulnerability.
The impact of CVE-2023-51689 is the potential for an attacker to execute malicious scripts in the context of a user's browser, compromising user data.