Vulnerability Description
The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Metaphorcreations | Ditty | < 3.1.25 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/aa39de78-55b3-4237-84db-6fdf6820c58dExploitThird Party Advisory
- https://wpscan.com/vulnerability/aa39de78-55b3-4237-84db-6fdf6820c58dExploitThird Party Advisory
FAQ
What is CVE-2023-4148?
CVE-2023-4148 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Ditty WordPress plugin before 3.1.25 does not sanitise and escape some parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which coul...
How severe is CVE-2023-4148?
CVE-2023-4148 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4148?
Check the references section above for vendor advisories and patch information. Affected products include: Metaphorcreations Ditty.