Lucene search

K
cvePatchstackCVE-2023-40206
HistorySep 04, 2023 - 11:15 a.m.

CVE-2023-40206

2023-09-0411:15:41
CWE-79
Patchstack
web.nvd.nist.gov
26
cve-2023-40206
auth
admin+
stored xss
cross-site scripting
xss
vulnerability
hwk-fr wp 404 auto redirect to similar post
nvd

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

21.6%

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in hwk-fr WP 404 Auto Redirect to Similar Post plugin <= 1.0.3 versions.

Affected configurations

Nvd
Vulners
Node
hwkwp_404_auto_redirect_to_similar_postRange1.0.3wordpress
VendorProductVersionCPE
hwkwp_404_auto_redirect_to_similar_post*cpe:2.3:a:hwk:wp_404_auto_redirect_to_similar_post:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "wp-404-auto-redirect-to-similar-post",
    "product": "WP 404 Auto Redirect to Similar Post",
    "vendor": "hwk-fr",
    "versions": [
      {
        "lessThanOrEqual": "1.0.3",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

4.8

Confidence

High

EPSS

0.001

Percentile

21.6%