CVE Vulnerabilities

CVE-2023-0420

Published: Apr 24, 2023 | Modified: Feb 04, 2025
CVSS 3.x
4.8
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising as well as escaping in some parameters, allowing attackers to make a logged in admin put Stored Cross-Site Scripting payloads via CSRF

Affected Software

NameVendorStart VersionEnd Version
Custom_post_type_and_taxonomy_gui_managerCustom_post_type_and_taxonomy_gui_manager_project*1.1 (including)

References