CVE-2023-1982
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Aug 30, 2023
Updated: Nov 7, 2023
Summary
CVE-2023-1982 is a vulnerability affecting the Front Editor WordPress plugin before version 4.0.5. This issue permits Stored Cross-Site Scripting (XSS) attacks against high-privilege users, bypassing the unfiltered_html capability restriction. The plugin fails to sanitize and escape certain form settings, leaving these input fields susceptible to malicious scripts. In multisite setups, this vulnerability could pose a significant risk to multiple sites on the same server.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share