NA

CVE-2023-2605

Published: 27/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The wpbrutalai WordPress plugin prior to 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

Vulnerable Product Search on Vulmon Subscribe to Product

wp brutal ai project wp brutal ai

Exploits

WordPress WP Brutal AI plugin versions prior to 201 suffer from a cross site scripting vulnerability ...