WordPress which template file Plugin <= 4.9.0 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-49177
What is CVE-2023-49177?
A Cross-Site Scripting (XSS) vulnerability exists in the Which Template File plugin created by Gilles Dumas. This vulnerability can be exploited through improper neutralization of user input during the generation of web pages, allowing attackers to inject arbitrary scripts into web pages viewed by other users. This issue affects versions ranging from n/a up to 4.9.0, posing significant security risks. It facilitates attackers to potentially take control of user sessions or redirect users to malicious sites. To protect against this vulnerability, it's crucial to update to the latest version of the plugin and implement best security practices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
which template file <= 4.9.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved