Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57860 | The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks. |
Fri, 22 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-11-21T19:17:14.770Z
Reserved: 2023-10-12T15:08:01.136Z
Link: CVE-2023-5560
Updated: 2024-08-02T07:59:44.715Z
Status : Modified
Published: 2023-11-27T17:15:08.980
Modified: 2024-11-21T08:42:01.083
Link: CVE-2023-5560
No data.
OpenCVE Enrichment
No data.
EUVD