CVE-2023-5354: Awesome Support < 6.1.5 - Reflected Cross-Site Scripting
The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-5354.
What is the severity of CVE-2023-5354?
The severity of CVE-2023-5354 is medium with a severity value of 6.1.
What is the description of CVE-2023-5354?
CVE-2023-5354 is a reflected cross-site scripting vulnerability in the Awesome Support WordPress plugin before version 6.1.5, allowing an attacker to execute malicious scripts on the affected pages.
What is the affected software by CVE-2023-5354?
The affected software by CVE-2023-5354 is the Awesome Support plugin for WordPress versions up to and excluding 6.1.5.
How can I mitigate CVE-2023-5354?
To mitigate CVE-2023-5354, it is recommended to update to version 6.1.5 or newer of the Awesome Support plugin for WordPress.