CVE-2023-51693: WordPress Themify Icons Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS)
Published Feb 1, 2024
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Icons allows Stored XSS.This issue affects Themify Icons: from n/a through 2.0.1.
Affected Software
1 affected component
Themify Icons Wordpress<=2.0.1
Remediation
Information
Update to 2.0.2 or a higher version.
Event History
Feb 1, 2024
CVE Published
via MITRE·11:02 AM
Data Sourced
via MITRE·11:02 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-51693?
CVE-2023-51693 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2023-51693?
To fix CVE-2023-51693, update Themify Icons to version 2.0.2 or later.
3
What software is affected by CVE-2023-51693?
CVE-2023-51693 affects Themify Icons versions up to and including 2.0.1.
4
What can happen if CVE-2023-51693 is exploited?
If exploited, CVE-2023-51693 can allow attackers to execute malicious scripts in the context of a user's session.
5
Is there a patch for CVE-2023-51693?
Yes, a patch is available with the release of Themify Icons version 2.0.2.