WordPress Simple URLs Plugin <= 117 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-40667

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
27 September 2023

Summary

The Lasso Simple URLs plugin for WordPress is prone to a reflected Cross-Site Scripting (XSS) vulnerability in versions 117 and earlier. This flaw allows attackers to inject malicious scripts into the web application's response, potentially leading to unauthorized access and data theft. Users with the affected plugin are urged to apply patches and update to secure their websites against possible exploitation.

Affected Version(s)

Simple URLs <= 117

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafshanzani Suhada (Patchstack Alliance)
.