CVE-2023-46091
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Oct 27, 2023
Updated: Nov 3, 2023
CWE ID 79
Summary
CVE-2023-46091 is a stored Cross-Site Scripting (XSS) vulnerability affecting the SEO Meta Tags plugin by Bala Krishna and Sergey Yakovlev, versions 2.5 and below. An attacker with administrative privileges can inject malicious scripts into a website's SEO meta tags, which are then executed when the page is loaded in a user's browser. This can lead to unintended actions such as data theft, session hijacking, or even complete website takeover. Administrators are advised to update the plugin to the latest version or disable it until a patch is available.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Balakrishna