CVE-2023-0490

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published May 15, 2023
Updated: Jan 14, 2025

Summary

CVE-2023-0490 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the f(x) TOC WordPress plugin before version 1.1.0. The issue lies in the plugin's failure to validate and escape shortcode attributes, allowing contributors and higher-level users to inject malicious code into pages and posts where the shortcode is embedded. This vulnerability poses a significant risk, as the injected scripts could be executed in the context of the vulnerable website, potentially leading to unauthorized account takeover, data theft, or other malicious activities. WordPress users are advised to update the plugin to its latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share