Stored Cross-Site Scripting Vulnerability in Simple Shopping Cart by WordPress
CVE-2023-6497
4.8MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 27 January 2024
What is CVE-2023-6497?
The Simple Shopping Cart plugin for WordPress has a vulnerability allowing for Stored Cross-Site Scripting due to inadequate input sanitization and output escaping. This issue permits attackers with administrator-level permissions to inject malicious web scripts via the automatic redirect URL setting. When users access affected pages, these injected scripts execute, posing a significant security threat. The vulnerability is present in all versions up to 4.7.1, particularly impacting multi-site installations or those where the unfiltered_html setting has been disabled.
Affected Version(s)
WordPress Simple Shopping Cart * <= 4.7.1