CVE-2023-6732: Ultimate Maps by Supsystic < 1.2.16 - Admin+ Stored XSS
The Ultimate Maps by Supsystic WordPress plugin before 1.2.16 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfilteredhtml is disallowed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6732?
CVE-2023-6732 is considered to have a high severity due to its potential for Cross-Site Scripting attacks.
How do I fix CVE-2023-6732?
To fix CVE-2023-6732, upgrade the Ultimate Maps by Supsystic WordPress plugin to version 1.2.16 or later.
Who is affected by CVE-2023-6732?
CVE-2023-6732 affects users of the Ultimate Maps by Supsystic WordPress plugin prior to version 1.2.16.
What kind of attack can be executed due to CVE-2023-6732?
CVE-2023-6732 can allow high privilege users to perform Cross-Site Scripting attacks.
Is unfiltered_html setting relevant for CVE-2023-6732?
Yes, CVE-2023-6732 can enable Cross-Site Scripting attacks even when the unfiltered_html setting is disallowed.