CVE-2023-6882: Simple Membership <= 4.3.8 - Reflected Cross-Site Scripting Vulnerability via environment_mode
The Simple Membership plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘environmentmode’ parameter in all versions up to, and including, 4.3.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6882?
CVE-2023-6882 is classified as a medium severity vulnerability due to the potential for reflected cross-site scripting attacks.
How do I fix CVE-2023-6882?
To fix CVE-2023-6882, update the Simple Membership plugin to version 4.3.9 or later, which includes patches for the vulnerability.
Who is affected by CVE-2023-6882?
CVE-2023-6882 affects all versions of the Simple Membership plugin for WordPress up to and including 4.3.8.
What type of vulnerability is CVE-2023-6882?
CVE-2023-6882 is a reflected cross-site scripting (XSS) vulnerability caused by insufficient input sanitization.
Can CVE-2023-6882 be exploited by unauthenticated users?
Yes, CVE-2023-6882 can be exploited by unauthenticated attackers, allowing them to inject arbitrary JavaScript.