CVE-2023-3412

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jun 27, 2023
Updated: Jan 13, 2025
CWE ID 287
CWE ID 305

Summary

CVE-2023-3412 is a Stored Cross-Site Scripting vulnerability affecting the Image Map Pro – Drag-and-drop Builder for Interactive Images – Lite plugin for WordPress. The issue lies in the ajax_store_save() function, where a capability check is missing. This deficiency enables authenticated attackers, even those with minimal permissions like subscribers, to manipulate plugin settings and insert malicious web scripts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • SonicWALL Global Management System

Affected Vendors

  • SonicWall Inc.