8.8
CVSSv3

CVE-2023-0603

Published: 08/05/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Sloth Logo Customizer WordPress plugin up to and including 2.0.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow malicious users to make logged in admin add Stored XSS payloads via a CSRF attack

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sloth logo customizer project sloth logo customizer