CVE Vulnerabilities

CVE-2023-3746

Published: Oct 16, 2023 | Modified: Apr 23, 2025
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks

Affected Software

NameVendorStart VersionEnd Version
ActivitypubAutomattic*1.0.0 (excluding)

References