CVE-2023-2489
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jun 5, 2023
Updated: Jan 8, 2025
CWE ID 122
Summary
CVE-2023-2489 is a vulnerability affecting the Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2023. This issue arises due to the plugin's failure to properly sanitize and escape certain settings. As a result, high privilege users, such as admins, can execute Stored Cross-Site Scripting attacks, bypassing the unfiltered_html capability restriction, even in multisite setups. This vulnerability poses a significant risk to WordPress websites using this plugin and requires immediate attention and patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Visual Studio 2019
- Microsoft Visual Studio 2017
- Microsoft Visual Studio 2022
- Microsoft Visual Studio 2019
- Microsoft .NET Framework
Affected Vendors
- Microsoft