CVE-2023-0490
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2023-0490 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the f(x) TOC WordPress plugin before version 1.1.0. The issue lies in the plugin's failure to validate and escape shortcode attributes, allowing contributors and higher-level users to inject malicious code into pages and posts where the shortcode is embedded. This vulnerability poses a significant risk, as the injected scripts could be executed in the context of the vulnerable website, potentially leading to unauthorized account takeover, data theft, or other malicious activities. WordPress users are advised to update the plugin to its latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.