Description
The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-33987 | The 10Web Social Post Feed WordPress plugin before 1.2.9 does not sanitise and escape some parameter before outputting it back in a page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin |
References
History
Wed, 08 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-01-08T17:07:14.045Z
Reserved: 2023-05-03T15:15:59.963Z
Link: CVE-2023-2503
Updated: 2024-08-02T06:26:08.476Z
Status : Modified
Published: 2023-06-05T14:15:10.300
Modified: 2025-01-08T18:15:14.640
Link: CVE-2023-2503
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD