CVE-2023-7168: Better Follow Button for Jetpack <= 8.0 - Admin+ Stored XSS
The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7168?
The severity of CVE-2023-7168 is considered to be high due to its potential for Stored Cross-Site Scripting attacks that could impact high privilege users.
How do I fix CVE-2023-7168?
To fix CVE-2023-7168, update the Better Follow Button for Jetpack plugin to version 8.1 or later, which addresses the vulnerability.
Who is affected by CVE-2023-7168?
CVE-2023-7168 affects users of the Better Follow Button for Jetpack WordPress plugin versions up to and including 8.0.
What types of attacks can CVE-2023-7168 allow?
CVE-2023-7168 can allow high privilege users to perform Stored Cross-Site Scripting attacks through improper sanitization of settings.
Is CVE-2023-7168 a critical vulnerability?
Yes, CVE-2023-7168 is classified as a critical vulnerability due to the risk it poses to website integrity and security.