WordPress Community by PeepSo Plugin <= 6.2.6.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-48746

7.1HIGH

What is CVE-2023-48746?

The PeepSo Community product is vulnerable to a reflected cross-site scripting (XSS) attack. This vulnerability allows an attacker to inject malicious scripts into web pages that are visible to users. When the manipulated page is accessed, the malicious scripts execute in the context of the user's browser, which could lead to various security issues such as data theft and unauthorized actions. Users of this product are advised to upgrade to mitigate the risk associated with this vulnerability.

Affected Version(s)

Community by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.2.6.0

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phd (Patchstack Alliance)
.