Vulnerability Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ginger Plugins Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button allows Stored XSS.This issue affects Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button: from n/a through 1.1.8.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gingerplugins | Sticky Chat Widget | <= 1.1.8 |
Related Weaknesses (CWE)
References
- https://patchstack.com/database/vulnerability/sticky-chat-widget/wordpress-stickThird Party Advisory
- https://patchstack.com/database/vulnerability/sticky-chat-widget/wordpress-stickThird Party Advisory
FAQ
What is CVE-2023-51361?
CVE-2023-51361 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ginger Plugins Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and...
How severe is CVE-2023-51361?
CVE-2023-51361 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-51361?
Check the references section above for vendor advisories and patch information. Affected products include: Gingerplugins Sticky Chat Widget.