CVE-2023-5228: User Registration < 3.0.4.2 - Admin+ Stored XSS
Published Nov 6, 2023
·Updated
The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
1 affected component
WPEverest User Registration Wordpress<3.0.4.2
Event History
Nov 6, 2023
CVE Published
via MITRE·08:40 PM
Data Sourced
via MITRE·08:40 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-5228.
2
What is the severity of CVE-2023-5228?
The severity of CVE-2023-5228 is medium with a CVSS score of 4.8.
3
How does the User Registration WordPress plugin version 3.0.4.2 and below get affected?
The User Registration WordPress plugin version 3.0.4.2 and below is affected by this vulnerability.
4
What is the impact of CVE-2023-5228?
The impact of CVE-2023-5228 is that high-privilege users, such as admin, can perform Stored Cross-Site Scripting attacks.
5
How do I fix CVE-2023-5228?
To fix CVE-2023-5228, you should update the User Registration WordPress plugin to version 3.0.4.3 or later.