NA

CVE-2023-1893

Published: 17/07/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Login Configurator WordPress plugin up to and including 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.

Vulnerable Product Search on Vulmon Subscribe to Product

login configurator project login configurator

Exploits

WordPress Login Configurator plugin version 21 and below suffer from a cross site scripting vulnerability ...