CVE-2023-6164: MainWP Dashboard <= 4.5.1.2 - Authenticated(Administrator+) CSS Injection
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary CSS values into the site tags.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-6164?
CVE-2023-6164 is a vulnerability found in the MainWP Dashboard plugin for WordPress versions up to 4.5.1.2 that allows for CSS Injection via the 'newColor' parameter.
How severe is CVE-2023-6164?
CVE-2023-6164 has a severity rating of 4.8, which is considered medium.
How does CVE-2023-6164 affect MainWP Dashboard?
CVE-2023-6164 affects MainWP Dashboard plugin for WordPress versions up to 4.5.1.2, allowing authenticated attackers to perform CSS Injection.
How can CVE-2023-6164 be fixed?
To fix CVE-2023-6164, users should update to the latest version of the MainWP Dashboard plugin (4.5.1.3), which contains the necessary security patches.
What is the CWE classification of CVE-2023-6164?
CVE-2023-6164 is classified under CWE-74 and CWE-79, which respectively refer to Improper Neutralization of Special Elements in Output Used by a Downstream Component and Improper Neutralization of Input During Web Page Generation.