{"id":"CVE-2023-1069","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-1069","summary":"Complianz WordPress plugin vulnerable to cross-site scripting","details":"The Complianz Premium WordPress plugin before 6.4.2 did not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.","published":"2023-03-27T18:30:26Z","modified":"2024-02-22T05:31:45.064288Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"really-simple-plugins/complianz-gdpr","fixedVersion":"6.4.2"}],"fix":{"url":"https://github.com/Really-Simple-Plugins/complianz-gdpr/commit/e6c2c386cadb78f8cdcded1b000cbd38bd9ff043","label":"Really-Simple-Plugins/complianz-gdpr@e6c2c38"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1069"},{"type":"WEB","url":"https://github.com/Really-Simple-Plugins/complianz-gdpr/commit/e6c2c386cadb78f8cdcded1b000cbd38bd9ff043"},{"type":"WEB","url":"https://wpscan.com/vulnerability/caacc50c-822e-46e9-bc0b-681349fd0dda"},{"type":"WEB","url":"www.github.com/Really-Simple-Plugins/complianz-gdpr"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-22T05:31:45.064288Z"}}