First published: Fri Oct 20 2023(Updated: )
The flowpaper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'flipbook' shortcode in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
PaperCut MF | <=2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5200 is a vulnerability in the flowpaper plugin for WordPress that allows for Stored Cross-Site Scripting via the 'flipbook' shortcode.
Versions up to and including 2.0.3 of the flowpaper plugin for WordPress are affected by CVE-2023-5200.
CVE-2023-5200 exploits the vulnerability by taking advantage of insufficient input sanitization and output escaping on user supplied attributes in the 'flipbook' shortcode.
CVE-2023-5200 has a severity value of 6.4, which is considered medium.
To fix the CVE-2023-5200 vulnerability, you should update the flowpaper plugin to a version higher than 2.0.3, where the issue has been addressed.