CVE-2023-0233
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published May 15, 2023
Updated: Jan 14, 2025
Summary
CVE-2023-0233 is a stored cross-site scripting (XSS) vulnerability affecting the ActiveCampaign WordPress plugin before version 8.1.12. malicious users with the contributor role or higher can exploit this flaw by injecting malicious scripts into block options. These scripts are not validated or escaped properly, allowing them to be executed when the block is rendered in a page or post. Successful attacks could lead to unintended user actions, data theft, or website defacement. Users are advised to update the plugin to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.