Stored Cross-Site Scripting in WP Post Columns Plugin for WordPress
CVE-2023-5708
6.4MEDIUM
What is CVE-2023-5708?
The WP Post Columns plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate sanitization and escaping of user-supplied attributes in the 'column' shortcode. This vulnerability affects all versions up to and including 2.2, enabling authenticated users with contributor-level permissions or higher to inject arbitrary scripts into pages. These scripts will execute whenever a user accesses the affected page, potentially compromising the site’s integrity and user security.
Affected Version(s)
WP Post Columns 0 <= 2.2