CVE-2023-47877
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Nov 30, 2023
Updated: Dec 6, 2023
CWE ID 79
Summary
CVE-2023-47877 is a Cross-site Scripting (XSS) vulnerability affecting Perfmatters, a performance optimization plugin for WordPress. The issue, present before version 2.2.0, allows an attacker to inject malicious scripts into web pages generated by Perfmatters, potentially leading to data theft or unauthorized account access. The vulnerability occurs due to improper neutralization of user inputs. By exploiting this flaw, an attacker can execute scripts in the context of other users, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share