CVE-2023-5757: WP Crowdfunding < 2.1.8 - Admin+ Stored XSS
Published Dec 11, 2023
·Updated
The WP Crowdfunding WordPress plugin before 2.1.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
1 affected component
Themeum Wp Crowdfunding Wordpress<2.1.8
Event History
Dec 11, 2023
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
DescriptionWeakness
May 24, 57290
Event
via FIRST·01:24 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-5757?
CVE-2023-5757 has a high severity rating due to its potential to allow stored cross-site scripting attacks.
2
How do I fix CVE-2023-5757?
To fix CVE-2023-5757, update the WP Crowdfunding plugin to version 2.1.8 or later.
3
Who is impacted by CVE-2023-5757?
CVE-2023-5757 impacts high privilege users, such as admin accounts, using the WP Crowdfunding plugin.
4
What kind of attack does CVE-2023-5757 allow?
CVE-2023-5757 allows for stored cross-site scripting (XSS) attacks.
5
What versions are affected by CVE-2023-5757?
CVE-2023-5757 affects WP Crowdfunding versions prior to 2.1.8.