Lucene search

K
cve[email protected]CVE-2023-47516
HistoryNov 13, 2023 - 4:15 a.m.

CVE-2023-47516

2023-11-1304:15:08
CWE-352
web.nvd.nist.gov
32
cve-2023-47516
csrf
vulnerability
stark digital
category post list widget
stored xss
nvd
security
information security

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

6.4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

Cross-Site Request Forgery (CSRF) vulnerability in Stark Digital Category Post List Widget allows Stored XSS.This issue affects Category Post List Widget: from n/a through 2.0.

Affected configurations

Vulners
NVD
Node
stark_digitalcategory_post_list_widgetRange2.0

CNA Affected

[
  {
    "collectionURL": "https://wordpress.org/plugins",
    "defaultStatus": "unaffected",
    "packageName": "category-post-list-widget",
    "product": "Category Post List Widget",
    "vendor": "Stark Digital",
    "versions": [
      {
        "lessThanOrEqual": "2.0",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

6.4 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.1%

Related for CVE-2023-47516