CVE-2023-6161

Severity
6.1MEDIUM
EPSS
0.3%
top 48.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8

Description

The WP Crowdfunding WordPress plugin before 2.1.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

CVEListV5unknown/wp_crowdfunding< 2.1.9

🔴Vulnerability Details

3
CVEList
WP Crowdfunding < 2.1.9 - Reflected XSS2024-01-08
GHSA
GHSA-m866-4h9x-6c44: The WP Crowdfunding WordPress plugin before 22024-01-08
OSV
dotnet6, dotnet7 regression2023-06-23
CVE-2023-6161 (MEDIUM CVSS 6.1) | The WP Crowdfunding WordPress plugi | cvebase.io