Severity
6.1MEDIUM
EPSS
0.1%
top 64.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateSep 15

Description

The W4 Post List WordPress plugin before 2.4.6 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
W4 Post List < 2.4.6 - Reflected XSS2023-04-17
GHSA
GHSA-hgqw-hh57-7q9g: The W4 Post List WordPress plugin before 22023-04-17

📋Vendor Advisories

1
Red Hat
kernel: firmware: dmi-sysfs: Fix null-ptr-deref in dmi_sysfs_register_handle2025-09-15
CVE-2023-1373 (MEDIUM CVSS 6.1) | The W4 Post List WordPress plugin b | cvebase.io