WordPress Simple URLs Plugin <= 117 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-40667
7.1HIGH
Summary
The Lasso Simple URLs plugin for WordPress is prone to a reflected Cross-Site Scripting (XSS) vulnerability in versions 117 and earlier. This flaw allows attackers to inject malicious scripts into the web application's response, potentially leading to unauthorized access and data theft. Users with the affected plugin are urged to apply patches and update to secure their websites against possible exploitation.
Affected Version(s)
Simple URLs <= 117
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafshanzani Suhada (Patchstack Alliance)