First published: Wed Nov 22 2023(Updated: )
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary CSS values into the site tags.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
MainWP | <=4.5.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6164 is a vulnerability found in the MainWP Dashboard plugin for WordPress versions up to 4.5.1.2 that allows for CSS Injection via the 'newColor' parameter.
CVE-2023-6164 has a severity rating of 4.8, which is considered medium.
CVE-2023-6164 affects MainWP Dashboard plugin for WordPress versions up to 4.5.1.2, allowing authenticated attackers to perform CSS Injection.
To fix CVE-2023-6164, users should update to the latest version of the MainWP Dashboard plugin (4.5.1.3), which contains the necessary security patches.
CVE-2023-6164 is classified under CWE-74 and CWE-79, which respectively refer to Improper Neutralization of Special Elements in Output Used by a Downstream Component and Improper Neutralization of Input During Web Page Generation.