CVE-2023-5609Cross-site Scripting in Seraphinite Accelerator

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 69.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 20

Description

The Seraphinite Accelerator WordPress plugin before 2.2.29 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

🔴Vulnerability Details

2
CVEList
Seraphinite Accelerator < 2.20.29 - Reflected XSS2023-11-20
GHSA
GHSA-4rfx-692g-gc7w: The Seraphinite Accelerator WordPress plugin before 22023-11-20
CVE-2023-5609 — Cross-site Scripting | cvebase