The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12640 | The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T05:17:50.079Z
Reserved: 2023-01-31T19:58:31.990Z
Link: CVE-2023-0602
No data.
Status : Modified
Published: 2023-07-31T10:15:10.333
Modified: 2024-11-21T07:37:28.103
Link: CVE-2023-0602
No data.
OpenCVE Enrichment
No data.
EUVD