Pular para o conteúdo
Ver todas as ameaças

CVE-2023-5237

Alvo: Não informado

Descrição

The Memberlite Shortcodes WordPress plugin before 1.3.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.

Software
Não informado
Tipo Software
Plugin
CVE
CVE-2023-5237
Tags
Nâo informado
Data de publicação
31/10/2023
Última atualização
09/11/2023
Pontuação em CVSS 3.0
5.4
Médio
plugins premium WordPress