CVE-2023-5237: Memberlite Shortcodes < 1.3.9 - Contributor+ Stored XSS via Shortcode
The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5237?
CVE-2023-5237 is a vulnerability in the Memberlite Shortcodes WordPress plugin before 1.3.9 that allows users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
Is the Memberlite Shortcodes plugin affected by CVE-2023-5237?
Yes, the Memberlite Shortcodes plugin version before 1.3.9 is affected by CVE-2023-5237.
What is the severity of CVE-2023-5237?
The severity of CVE-2023-5237 is medium, with a severity value of 5.4.
How can an attacker exploit CVE-2023-5237?
An attacker with a role as low as contributor can exploit CVE-2023-5237 by performing Stored Cross-Site Scripting attacks using certain shortcode attributes.
What is the recommended fix for CVE-2023-5237?
To fix CVE-2023-5237, users should update the Memberlite Shortcodes plugin to version 1.3.9 or later.