CVE-2023-6526: Meta Box – WordPress Custom Fields Framework <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Meta Box – WordPress Custom Fields Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta values displayed through the plugin's shortcode in all versions up to, and including, 5.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6526?
CVE-2023-6526 has been rated as a medium severity vulnerability.
How do I fix CVE-2023-6526?
To fix CVE-2023-6526, update the Meta Box plugin to version 5.9.3 or later.
What type of vulnerability is CVE-2023-6526?
CVE-2023-6526 is a Stored Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2023-6526?
All users of the Meta Box plugin for WordPress up to and including version 5.9.2 are affected by CVE-2023-6526.
Can CVE-2023-6526 be exploited remotely?
Yes, CVE-2023-6526 can be exploited remotely if an attacker injects malicious script through custom post meta values.