WordPress YML for Yandex Market Plugin <= 3.10.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-30473

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 August 2023

What is CVE-2023-30473?

This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript code in the context of a user's browser session by exploiting the YML for Yandex Market plugin in WordPress versions up to 3.10.7. This occurs due to improper sanitization and validation of user input, which can lead to reflective XSS attacks, compromising user data and broader site security.

Affected Version(s)

YML for Yandex Market <= 3.10.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LEE SE HYOUNG (Patchstack Alliance)
.