NA

CVE-2023-6268

Published: 26/12/2023 Updated: 04/01/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The JSON Content Importer WordPress plugin prior to 1.5.4 does not sanitise and escape the tab parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Vulnerable Product Search on Vulmon Subscribe to Product

json-content-importer json content importer