CVE-2023-1982

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Aug 30, 2023
Updated: Nov 7, 2023

Summary

CVE-2023-1982 is a vulnerability affecting the Front Editor WordPress plugin before version 4.0.5. This issue permits Stored Cross-Site Scripting (XSS) attacks against high-privilege users, bypassing the unfiltered_html capability restriction. The plugin fails to sanitize and escape certain form settings, leaving these input fields susceptible to malicious scripts. In multisite setups, this vulnerability could pose a significant risk to multiple sites on the same server.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share