CVE Vulnerabilities

CVE-2023-0603

Published: May 08, 2023 | Modified: Apr 23, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Sloth Logo Customizer WordPress plugin through 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

Affected Software

NameVendorStart VersionEnd Version
Sloth_logo_customizerSloth_logo_customizer_project*2.0.2 (including)

References