CVE-2023-5432: Jquery news ticker <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Jquery news ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'jquery-news-ticker' shortcode in versions up to, and including, 3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5432?
CVE-2023-5432 has a medium severity rating due to its potential for exploitation through Stored Cross-Site Scripting.
How do I fix CVE-2023-5432?
To fix CVE-2023-5432, update the Jquery News Ticker plugin to version 3.2 or higher where the vulnerability has been resolved.
What versions are affected by CVE-2023-5432?
CVE-2023-5432 affects Jquery News Ticker plugin versions up to and including 3.1.
What type of vulnerability is CVE-2023-5432?
CVE-2023-5432 is a Stored Cross-Site Scripting vulnerability caused by inadequate input sanitization and output escaping.
Who can exploit CVE-2023-5432?
CVE-2023-5432 can be exploited by authenticated attackers who can inject malicious scripts via the 'jquery-news-ticker' shortcode.