Lucene search

K
cvePatchstackCVE-2023-30471
HistorySep 27, 2023 - 3:18 p.m.

CVE-2023-30471

2023-09-2715:18:51
CWE-79
Patchstack
web.nvd.nist.gov
14
cve-2023-30471
unauthenticated
reflected
cross-site scripting
xss
cornel raiu
wp search analytics
nvd

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

AI Score

6

Confidence

High

EPSS

0.001

Percentile

20.2%

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cornel Raiu WP Search Analytics plugin <=Β 1.4.7 versions.

Affected configurations

Nvd
Vulners
Node
cornelraiuwp_search_analyticsRange<1.4.8wordpress
VendorProductVersionCPE
cornelraiuwp_search_analytics*cpe:2.3:a:cornelraiu:wp_search_analytics:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "search-analytics",
    "product": "WP Search Analytics",
    "vendor": "Cornel Raiu",
    "versions": [
      {
        "changes": [
          {
            "at": "1.4.8",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "1.4.7",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

AI Score

6

Confidence

High

EPSS

0.001

Percentile

20.2%

Related for CVE-2023-30471