CVE-2023-3412
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Jun 27, 2023
Updated: Jan 13, 2025
CWE ID 287
CWE ID 305
Summary
CVE-2023-3412 is a Stored Cross-Site Scripting vulnerability affecting the Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress. The issue lies in the ajax_store_save() function, where a capability check is missing. This deficiency enables authenticated attackers, even those with minimal permissions like subscribers, to manipulate plugin settings and insert malicious web scripts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SonicWALL Global Management System
Affected Vendors
- SonicWall Inc.