CVE-2023-3746

Severity
5.4MEDIUM
EPSS
0.1%
top 70.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16

Description

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/activitypub< 1.0.0

🔴Vulnerability Details

2
GHSA
GHSA-32jc-368c-fvg6: The ActivityPub WordPress plugin before 12023-10-16
CVEList
ActivityPub for WordPress < 1.0.1 - Contributor+ Stored XSS2023-10-16
CVE-2023-3746 (MEDIUM CVSS 5.4) | The ActivityPub WordPress plugin be | cvebase.io