CVE-2023-52118: WordPress WP User Profile Avatar Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP User Profile Avatar allows Stored XSS.This issue affects WP User Profile Avatar: from n/a through 1.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52118?
CVE-2023-52118 has been classified as a high severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2023-52118?
To mitigate CVE-2023-52118, update the WP User Profile Avatar plugin to the latest version that addresses the XSS vulnerability.
What is the impact of CVE-2023-52118 on affected systems?
CVE-2023-52118 can allow attackers to execute arbitrary JavaScript in the context of a user's session, potentially leading to data theft or account compromise.
Which versions are affected by CVE-2023-52118?
CVE-2023-52118 affects WP User Profile Avatar versions up to and including 1.0.
Is CVE-2023-52118 a common vulnerability?
Yes, CVE-2023-52118 represents a common type of vulnerability known as cross-site scripting, which is frequently found in web applications.