CVE-2023-0374

Severity
5.4MEDIUM
EPSS
0.1%
top 66.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17

Description

The W4 Post List WordPress plugin before 2.4.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
W4 Post List < 2.4.6 - Contributor+ Stored XSS2023-04-17
GHSA
GHSA-r6hq-mwrm-ppjg: The W4 Post List WordPress plugin before 22023-04-17
CVE-2023-0374 (MEDIUM CVSS 5.4) | The W4 Post List WordPress plugin b | cvebase.io