CVE-2023-6990: Weaver Xtreme <= 6.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Weaver Xtreme theme for WordPress is vulnerable to Stored Cross-Site Scripting via custom post meta in all versions up to, and including, 6.3.0 due to insufficient input sanitization and output escaping on user supplied meta (page-head-code). This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6990?
CVE-2023-6990 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2023-6990?
You can fix CVE-2023-6990 by updating the Weaver Xtreme theme to the latest version beyond 6.3.0, which addresses the input sanitization issue.
Who is affected by CVE-2023-6990?
CVE-2023-6990 affects all users of the Weaver Xtreme theme for WordPress versions up to and including 6.3.0.
What types of attacks can be carried out due to CVE-2023-6990?
CVE-2023-6990 allows authenticated attackers to perform stored cross-site scripting attacks through malicious custom post meta.
When was CVE-2023-6990 disclosed?
CVE-2023-6990 was disclosed in the first half of 2023, although the exact date of disclosure is not specified.