CVE-2023-5738: WordPress Backup & Migration < 1.4.5 - Subscriber+ Stored XSS
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5738?
The severity of CVE-2023-5738 is medium, with a CVSS score of 5.4.
How does CVE-2023-5738 affect WordPress Backup & Migration plugin?
CVE-2023-5738 affects WordPress Backup & Migration plugin before version 1.4.4, allowing users with low privileges such as Subscriber to perform Cross-Site Scripting attacks.
What is the CWE of CVE-2023-5738?
CVE-2023-5738 is associated with CWE-79, which is the Cross-Site Scripting (XSS) vulnerability.
How can I fix the vulnerability in WordPress Backup & Migration plugin?
To fix the vulnerability in WordPress Backup & Migration plugin, update to version 1.4.5 or higher.
Where can I find more information about CVE-2023-5738?
You can find more information about CVE-2023-5738 at the following reference: [link](https://wpscan.com/vulnerability/7f935916-9a1a-40c7-b6d8-efcc46eb8eaf)