CVE Vulnerabilities

CVE-2023-0602

Published: Jul 31, 2023 | Modified: Nov 07, 2023
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugins administrative page, which allows reflected XSS attacks targeting administrators to happen.

Affected Software

Name Vendor Start Version End Version
Twittee_text_tweet Johnniejodelljr * 1.0.8 (including)

References