Description
The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33852 | The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin |
References
History
Mon, 05 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Wow-company
Subscribe
Bubble Menu
Subscribe
Button Generator
Subscribe
Calculator-builder
Subscribe
Counter Box
Subscribe
Float Menu
Subscribe
Floating Button
Subscribe
Herd Effects
Subscribe
Popup Box
Subscribe
Side Menu Lite
Subscribe
Sticky Buttons
Subscribe
Wow Skype Buttons
Subscribe
Wp Coder
Subscribe
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-05-05T16:01:12.174Z
Reserved: 2023-04-28T10:05:48.876Z
Link: CVE-2023-2362
Updated: 2024-08-02T06:19:14.896Z
Status : Modified
Published: 2023-06-12T18:15:09.973
Modified: 2025-05-05T16:15:35.577
Link: CVE-2023-2362
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD