WordPress Simple URLs Plugin <= 117 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-40667
7.1HIGH
What is CVE-2023-40667?
The Lasso Simple URLs plugin for WordPress is prone to a reflected Cross-Site Scripting (XSS) vulnerability in versions 117 and earlier. This flaw allows attackers to inject malicious scripts into the web application's response, potentially leading to unauthorized access and data theft. Users with the affected plugin are urged to apply patches and update to secure their websites against possible exploitation.
Affected Version(s)
Simple URLs <= 117