Stored Cross-Site Scripting Vulnerability in WP Meta SEO Plugin Affects WordPress Pages
CVE-2023-6961

7.2HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
2 May 2024

Summary

The WP Meta SEO plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) vulnerabilities that arise from improper handling of the 'Referer' header. This flaw, present in all versions up to and including 4.5.12, allows unauthenticated attackers to inject malicious scripts into web pages. When users access these compromised pages, the injected scripts are executed, potentially leading to unauthorized actions and data exposure. The root causes include insufficient input sanitization and poor output escaping practices, emphasizing the need for developers to adhere to secure coding guidelines.

Affected Version(s)

WP Meta SEO * <= 4.5.12

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Zając
.