Description
The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57400 | The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks |
References
History
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T07:44:53.809Z
Reserved: 2023-09-18T20:14:19.297Z
Link: CVE-2023-5057
No data.
Status : Modified
Published: 2023-10-16T20:15:17.573
Modified: 2024-11-21T08:40:59.393
Link: CVE-2023-5057
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.
EUVD