Description
The Lana Shortcodes WordPress plugin before 1.2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which allows users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 20 Jun 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-06-20T17:01:54.093Z
Reserved: 2023-06-22T19:47:05.619Z
Link: CVE-2023-3372
Updated: 2024-08-02T06:55:03.154Z
Status : Modified
Published: 2024-01-16T16:15:11.350
Modified: 2025-06-20T17:15:31.110
Link: CVE-2023-3372
No data.
OpenCVE Enrichment
No data.
Weaknesses