The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This is due to an insufficient fix of CVE-2023-24003
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/b6ac3e15-6f39-4514-a50d-cca7b9457736 | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-05-08 14:15
Updated : 2023-11-07 04:05
NVD link : CVE-2023-1905
Mitre link : CVE-2023-1905
CVE.ORG link : CVE-2023-1905
JSON object : View
Products Affected
timersys
- wp_popups
CWE
No CWE.