WordPress YML for Yandex Market Plugin <= 3.10.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-30473
7.1HIGH
What is CVE-2023-30473?
This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript code in the context of a user's browser session by exploiting the YML for Yandex Market plugin in WordPress versions up to 3.10.7. This occurs due to improper sanitization and validation of user input, which can lead to reflective XSS attacks, compromising user data and broader site security.
Affected Version(s)
YML for Yandex Market <= 3.10.7