CVE-2023-52124: WordPress WP Tabs Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC WP Tabs – Responsive Tabs Plugin for WordPress allows Stored XSS.This issue affects WP Tabs – Responsive Tabs Plugin for WordPress: from n/a through 2.2.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52124?
CVE-2023-52124 is classified as a high-severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2023-52124?
To fix CVE-2023-52124, update the WP Tabs – Responsive Tabs Plugin for WordPress to version 2.2.1 or later.
What causes CVE-2023-52124?
CVE-2023-52124 is caused by improper neutralization of user input during web page generation, allowing for stored XSS vulnerabilities.
Which versions of the WP Tabs – Responsive Tabs Plugin are affected by CVE-2023-52124?
CVE-2023-52124 affects all versions of the WP Tabs – Responsive Tabs Plugin for WordPress up to and including version 2.2.0.
Can CVE-2023-52124 lead to data theft?
Yes, CVE-2023-52124 can lead to data theft as attackers can execute malicious scripts in the context of a user's session.