WordPress Enfold Theme <= 5.6.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-38400
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 November 2023
What is CVE-2023-38400?
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Enfold - Responsive Multi-Purpose Theme, which can allow attackers to inject malicious scripts into web pages. This vulnerability could be exploited by an attacker to execute arbitrary JavaScript in the context of a user's session, potentially leading to unauthorized access and information theft. Websites using affected versions of this theme should apply updates promptly to mitigate risks.
Affected Version(s)
Enfold - Responsive Multi-Purpose Theme <= 5.6.4