Lucene search

K
cvelistWPScanCVELIST:CVE-2023-0603
HistoryMay 08, 2023 - 1:58 p.m.

CVE-2023-0603 Sloth Logo Customizer <= 2.0.2 - Stored XSS via CSRF

2023-05-0813:58:23
WPScan
www.cve.org
3
cve-2023-0603
stored xss
csrf
wordpress plugin
csrf attack

AI Score

8.3

Confidence

High

EPSS

0.002

Percentile

57.1%

The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "Sloth Logo Customizer",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThanOrEqual": "2.0.2"
      }
    ],
    "defaultStatus": "affected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

AI Score

8.3

Confidence

High

EPSS

0.002

Percentile

57.1%

Related for CVELIST:CVE-2023-0603