First published: Wed Mar 20 2024(Updated: )
The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bowo System Dashboard | <2.8.10 | |
WordPress System Dashboard | <2.8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-7246 is classified as high due to its potential for Cross-Site Scripting attacks.
To fix CVE-2023-7246, you should update the WordPress System Dashboard plugin to version 2.8.10 or later.
CVE-2023-7246 affects administrators using the System Dashboard plugin in multisite WordPress configurations.
CVE-2023-7246 is a Cross-Site Scripting (XSS) vulnerability that arises from improper sanitization and escaping of parameters.
Yes, CVE-2023-7246 can be exploited remotely by attackers targeting vulnerable installations of the plugin.