Lucene search

K
cvelistPatchstackCVELIST:CVE-2023-32241
HistoryAug 29, 2023 - 8:11 p.m.

CVE-2023-32241 WordPress Essential Addons for Elementor Pro Plugin <= 5.4.8 is vulnerable to Cross Site Scripting (XSS)

2023-08-2920:11:55
CWE-79
Patchstack
www.cve.org
5
cve-2023-32241
wordpress
elementor pro plugin
cross site scripting
unauthenticated
reflected
vulnerability

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

27.9%

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPDeveloper Essential Addons for Elementor Pro plugin <=Β 5.4.8 versions.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Essential Addons for Elementor Pro",
    "vendor": "WPDeveloper",
    "versions": [
      {
        "changes": [
          {
            "at": "5.4.9",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "5.4.8",
        "status": "affected",
        "version": "n/a",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

27.9%

Related for CVELIST:CVE-2023-32241