CVE-2023-4823

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Oct 31, 2023
Updated: Nov 8, 2023
CWE ID 755

Summary

CVE-2023-4823 is a vulnerability affecting the WP Meta and Date Remover WordPress plugin before version 2.2.0. The issue stems from an unsecured AJAX endpoint, which lacks capability checks and fails to sanitize user input. Consequently, authenticated users, including subscribers, can inject and execute malicious Stored Cross-Site Scripting (XSS) codes, posing a significant risk to websites utilizing this plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share