Lucene search

K
cveWPScanCVE-2023-0175
HistoryMar 20, 2023 - 4:15 p.m.

CVE-2023-0175

2023-03-2016:15:11
WPScan
web.nvd.nist.gov
31
cve-2023-0175
wordpress
security
plugin vulnerability
xss
nvd

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

23.3%

The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected configurations

Nvd
Vulners
Node
accesspressthemessmart_logo_showcase_liteMatch1.0.0wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.0.1wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.0.2wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.0.3wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.0.4wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.0.5wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.0.6wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.0.7wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.0.8wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.0.9wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.0wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.1wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.2wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.3wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.4wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.5wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.6wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.7wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.8wordpress
OR
accesspressthemessmart_logo_showcase_liteMatch1.1.9wordpress
VendorProductVersionCPE
accesspressthemessmart_logo_showcase_lite1.0.0cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.0:*:*:*:*:wordpress:*:*
accesspressthemessmart_logo_showcase_lite1.0.1cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.1:*:*:*:*:wordpress:*:*
accesspressthemessmart_logo_showcase_lite1.0.2cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.2:*:*:*:*:wordpress:*:*
accesspressthemessmart_logo_showcase_lite1.0.3cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.3:*:*:*:*:wordpress:*:*
accesspressthemessmart_logo_showcase_lite1.0.4cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.4:*:*:*:*:wordpress:*:*
accesspressthemessmart_logo_showcase_lite1.0.5cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.5:*:*:*:*:wordpress:*:*
accesspressthemessmart_logo_showcase_lite1.0.6cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.6:*:*:*:*:wordpress:*:*
accesspressthemessmart_logo_showcase_lite1.0.7cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.7:*:*:*:*:wordpress:*:*
accesspressthemessmart_logo_showcase_lite1.0.8cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.8:*:*:*:*:wordpress:*:*
accesspressthemessmart_logo_showcase_lite1.0.9cpe:2.3:a:accesspressthemes:smart_logo_showcase_lite:1.0.9:*:*:*:*:wordpress:*:*
Rows per page:
1-10 of 201

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Responsive Clients Logo Gallery Plugin for WordPress",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThanOrEqual": "1.1.9"
      }
    ],
    "defaultStatus": "affected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

23.3%

Related for CVE-2023-0175