Stored Cross-Site Scripting Vulnerability in Blog Filter Plugin for WordPress
CVE-2023-5291
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 October 2023
What is CVE-2023-5291?
The Blog Filter plugin for WordPress suffers from a Stored Cross-Site Scripting issue due to inadequate sanitization of user input and escaping of output. This vulnerability impacts versions up to and including 1.5.3. Authenticated attackers with contributor-level roles can exploit this risk by using the 'AWL-BlogFilter' shortcode to inject malicious web scripts into pages. The injected scripts execute whenever any user accesses these compromised pages, potentially leading to unauthorized actions or data theft.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Blog Filter β Advanced Post Filtering with Categories Or Tags, Post Portfolio Gallery, Blog Design Template, Post Layout * <= 1.5.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved