CVE-2023-6556
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 11, 2024
Updated: Jan 17, 2024
CWE ID 79
Summary
CVE-2023-6556 is a Stored Cross-Site Scripting vulnerability affecting the FOX – Currency Switcher Professional plugin for WordPress up to version 1.4.1.5. This issue arises from insufficient input sanitization and output escaping in the plugin's currency options feature. Authenticated attackers with subscriber-level access or higher can exploit this weakness and inject arbitrary web scripts. These scripts will execute whenever a user accesses an injected page, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share