CVE-2023-4823
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Oct 31, 2023
Updated: Nov 8, 2023
CWE ID 755
Summary
CVE-2023-4823 is a vulnerability affecting the WP Meta and Date Remover WordPress plugin before version 2.2.0. The issue stems from an unsecured AJAX endpoint, which lacks capability checks and fails to sanitize user input. Consequently, authenticated users, including subscribers, can inject and execute malicious Stored Cross-Site Scripting (XSS) codes, posing a significant risk to websites utilizing this plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share