CVE-2023-5614: Theme Switcha <= 3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Theme Switcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themeswitchalist' shortcode in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-5614?
CVE-2023-5614 is a vulnerability found in the Theme Switcha plugin for WordPress that allows for Stored Cross-Site Scripting through the 'theme_switcha_list' shortcode.
How severe is CVE-2023-5614?
CVE-2023-5614 has a severity rating of medium with a CVSS score of 6.4.
Which versions of the Theme Switcha plugin are affected by CVE-2023-5614?
All versions up to and including 3.3 of the Theme Switcha plugin for WordPress are affected by CVE-2023-5614.
How can the Stored Cross-Site Scripting vulnerability in CVE-2023-5614 be exploited?
The vulnerability can be exploited by injecting malicious scripts through the 'theme_switcha_list' shortcode in the Theme Switcha plugin for WordPress.
Is there a fix available for CVE-2023-5614?
Yes, users should update to the latest version of the Theme Switcha plugin (version 3.4 or higher) to fix CVE-2023-5614.