First published: Tue Oct 31 2023(Updated: )
The E2Pdf WordPress plugin before 1.20.20 does not sanitize and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
E2pdf | <1.20.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-5229.
The title of the vulnerability is E2Pdf < 1.20.20 - Admin+ Stored Cross-Site Scriping.
The severity of CVE-2023-5229 is medium.
The affected software is E2Pdf WordPress plugin before 1.20.20.
The vulnerability can be exploited by high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
To fix CVE-2023-5229, update the E2Pdf WordPress plugin to version 1.20.20 or later.