WordPress Video Grid Plugin <= 1.21 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-30785

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 August 2023

What is CVE-2023-30785?

This vulnerability allows remote attackers to execute arbitrary JavaScript code in the context of the user's browser, potentially leading to session hijacking and data leakage. The issue resides in the I Thirteen Web Solution Video Grid Plugin versions up to 1.21 where the absence of adequate input sanitization enables attackers to manipulate and inject malicious scripts through URL parameters.

Affected Version(s)

Video Grid <= 1.21

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yuyudhn (Patchstack Alliance)
.