WordPress Tainacan Plugin <= 0.20.4 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-47848
7.1HIGH
What is CVE-2023-47848?
The Tainacan plugin for WordPress is susceptible to a reflected cross-site scripting (XSS) vulnerability, which can be exploited by attackers to inject malicious scripts into web pages viewed by users. This flaw allows an unauthorized party to execute arbitrary JavaScript in the context of the user’s session, potentially leading to data theft and session hijacking. The vulnerability affects Tainacan from an unspecified version to 0.20.4, emphasizing the need for users to update to secure versions and implement enhanced input validation measures.
Affected Version(s)
Tainacan <= 0.20.4