CVE-2023-6555: Email Subscription Popup < 1.2.20 - Reflected XSS
Published Jan 8, 2024
·Updated
The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Affected Software
1 affected component
I13websolution Email Subscription Popup Wordpress<1.2.20
Event History
Jan 8, 2024
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-6555?
CVE-2023-6555 is categorized as a high severity vulnerability due to its potential impact on high privilege users.
2
How do I fix CVE-2023-6555?
To fix CVE-2023-6555, update the Email Subscription Popup plugin to version 1.2.20 or later.
3
What types of attacks can exploit CVE-2023-6555?
CVE-2023-6555 can be exploited through Reflected Cross-Site Scripting attacks.
4
Who is primarily affected by CVE-2023-6555?
High privilege users, such as administrators, are primarily affected by CVE-2023-6555.
5
What causes the vulnerability in CVE-2023-6555?
CVE-2023-6555 is caused by the plugin's failure to properly sanitize and escape user input before rendering it on the page.