Vulnerability Description
The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. This is due to an insufficient fix of CVE-2023-24003
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Timersys | Wp Popups | < 2.1.5.1 |
References
- https://wpscan.com/vulnerability/b6ac3e15-6f39-4514-a50d-cca7b9457736ExploitThird Party Advisory
- https://wpscan.com/vulnerability/b6ac3e15-6f39-4514-a50d-cca7b9457736ExploitThird Party Advisory
FAQ
What is CVE-2023-1905?
CVE-2023-1905 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The WP Popups WordPress plugin before 2.1.5.1 does not properly escape the href attribute of its spu-facebook-page shortcode before outputting it back in a page/post where the shortcode is embed, whic...
How severe is CVE-2023-1905?
CVE-2023-1905 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-1905?
Check the references section above for vendor advisories and patch information. Affected products include: Timersys Wp Popups.