CVE-2023-1602
Dashboard / Vulnerabilities / CVE-2023-1602
CVE-2023-1602
Summary:
Details: The Short URL plugin for WordPress is vulnerable to stored Cross-Site Scripting via the 'comment' parameter due to insufficient input sanitization and output escaping in versions up to, and including, 1.6.4. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
References: , https://wordpress.org/plugins/shorten-url/#developers, https://www.wordfence.com/threat-intel/vulnerabilities/id/a5f29f35-da79-4389-a0a5-a1be0b0b8996?source=cve, https://plugins.trac.wordpress.org/changeset/2931815/shorten-url/trunk/shorten-url.php
Affected packages
Package
Name:
Purl:
Affected ranges
Type: N/A
Events:
