First published: Fri Oct 20 2023(Updated: )
The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'theme_switcha_list' shortcode in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
<=3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5614 is a vulnerability found in the Theme Switcha plugin for WordPress that allows for Stored Cross-Site Scripting through the 'theme_switcha_list' shortcode.
CVE-2023-5614 has a severity rating of medium with a CVSS score of 6.4.
All versions up to and including 3.3 of the Theme Switcha plugin for WordPress are affected by CVE-2023-5614.
The vulnerability can be exploited by injecting malicious scripts through the 'theme_switcha_list' shortcode in the Theme Switcha plugin for WordPress.
Yes, users should update to the latest version of the Theme Switcha plugin (version 3.4 or higher) to fix CVE-2023-5614.