CVE-2023-6050

Severity
6.1MEDIUM
EPSS
0.1%
top 71.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15

Description

The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not sanitise and escape various parameters and generated URLs before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

🔴Vulnerability Details

3
CVEList
Estatik Real Estate Plugin < 4.1.1 - Reflected XSS2024-01-15
GHSA
GHSA-x2vc-c3wq-5j89: The Estatik Real Estate Plugin WordPress plugin before 42024-01-15
OSV
git vulnerabilities2023-05-17
CVE-2023-6050 (MEDIUM CVSS 6.1) | The Estatik Real Estate Plugin Word | cvebase.io