Vulnerability Description
The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be used against high privilege users such as admin
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mpembed | Wp Matterport Shortcode | < 2.1.7 |
References
- https://wpscan.com/vulnerability/5fad5245-a089-4ba3-9958-1e2c3d066eeaExploitThird Party Advisory
- https://wpscan.com/vulnerability/5fad5245-a089-4ba3-9958-1e2c3d066eeaExploitThird Party Advisory
FAQ
What is CVE-2023-4290?
CVE-2023-4290 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The WP Matterport Shortcode WordPress plugin before 2.1.7 does not escape the PHP_SELF server variable when outputting it in attributes, leading to Reflected Cross-Site Scripting issues which could be...
How severe is CVE-2023-4290?
CVE-2023-4290 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-4290?
Check the references section above for vendor advisories and patch information. Affected products include: Mpembed Wp Matterport Shortcode.