6.1
CVSSv3

CVE-2023-0099

Published: 13/02/2023 Updated: 05/02/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Simple URLs WordPress plugin prior to 115 does not sanitise and escape some parameters before outputting them back in some pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

getlasso simple urls

Exploits

WordPress Simple URLs plugin versions prior to 115 suffer from a cross site scripting vulnerability ...

Github Repositories

simple urls < 115 - Reflected XSS

CVE-2023-0099-exploit Exploit Title: simple urls &lt; 115 - Reflected XSS Google Dork: Exploit Author: AmirZargham Vendor Homepage: getlassoco/ Software Link: wordpressorg/plugins/simple-urls/ Version: &lt; 115 Tested on: firefox,chrome CVE: CVE-2023-0099 CWE: CWE-79 Platform: MULTIPLE Type: WebApps Description The Simple URLs WordPress plugin before 1