CVE-2023-5230
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Sep 28, 2023
Updated: Nov 7, 2023
CWE ID 787
CWE ID 120
Summary
CVE-2023-5230 is a stored cross-site scripting (XSS) vulnerability affecting the TM WooCommerce Compare & Wishlist plugin for WordPress. This issue, present in versions up to 1.1.7, stems from insufficient sanitization and output escaping on user-supplied attributes in the 'tm_woo_wishlist_table' shortcode. Authenticated attackers with contributor-level access or higher can exploit this vulnerability to inject arbitrary web scripts into pages. These scripts will execute whenever a user accesses an injected page, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share