WordPress WP-dTree Plugin <= 4.4.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-41662

7.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
29 September 2023

What is CVE-2023-41662?

A reflected cross-site scripting (XSS) vulnerability has been identified in the WP-dTree plugin by Ulf Benjaminsson, affecting all versions up to 4.4.5. This vulnerability allows unauthorized users to inject malicious scripts into webpages, which can be executed in the context of the victim’s browser. Attackers can exploit this flaw to steal sensitive information, manipulate user sessions, or redirect users to malicious sites. It is crucial for users of the affected plugin to apply the necessary updates to safeguard their WordPress sites.

Affected Version(s)

WP-dTree <= 4.4.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Le Ngoc Anh (Patchstack Alliance)
.