Vulnerability Description
The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfiltered_html capability is disabled, such as in a multisite setup.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Autoptimize | Autoptimize | < 3.1.7 |
References
- https://wpscan.com/vulnerability/ddb4c95d-bbee-4095-aed6-25f6b8e63011Exploit
- https://wpscan.com/vulnerability/ddb4c95d-bbee-4095-aed6-25f6b8e63011Exploit
FAQ
What is CVE-2023-2113?
CVE-2023-2113 is a vulnerability with a CVSS score of 4.8 (MEDIUM). The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary j...
How severe is CVE-2023-2113?
CVE-2023-2113 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2113?
Check the references section above for vendor advisories and patch information. Affected products include: Autoptimize Autoptimize.