CVE-2023-50376Cross-site Scripting in Wp.insider Simple Membership

Severity
6.1MEDIUMNVD
CNA7.1
EPSS
0.1%
top 67.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 19

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp.Insider Simple Membership allows Reflected XSS.This issue affects Simple Membership: from n/a through 4.3.8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
WordPress Simple Membership Plugin <= 4.3.8 is vulnerable to Unauth. Reflected Cross Site Scripting (XSS)2023-12-19
GHSA
GHSA-8cp3-ghqm-6565: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smp7, wp2023-12-19
CVE-2023-50376 — Cross-site Scripting | cvebase