CVE-2023-2362
Last modified
CVE-2023-2362 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wow-Company | Bubble Menu | < 3.0.4 |
| Wow-Company | Button Generator | < 2.3.5 |
| Wow-Company | Calculator-Builder | < 1.5.1 |
| Wow-Company | Counter Box | < 1.2.2 |
| Wow-Company | Float Menu | < 5.0.2 |
| Wow-Company | Floating Button | < 5.3.1 |
| Wow-Company | Herd Effects | < 5.2.2 |
| Wow-Company | Popup Box | < 2.2.2 |
| Wow-Company | Side Menu Lite | < 4.0.2 |
| Wow-Company | Sticky Buttons | < 3.1.1 |
| Wow-Company | Wow Skype Buttons | < 4.0.2 |
| Wow-Company | Wp Coder | < 2.5.6 |
References
- https://wpscan.com/vulnerability/27e70507-fd68-4915-88cf-0b96ed55208eExploit, Third Party Advisory
- https://wpscan.com/vulnerability/27e70507-fd68-4915-88cf-0b96ed55208eExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-2362?
How severe is CVE-2023-2362?
How do I fix CVE-2023-2362?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-23614Pi-hole®'s Web interface (based off of AdminLTE) provides a …8.8
- CVE-2023-23615Discourse is an open source discussion platform. The embedda…5.3
- CVE-2023-23616Discourse is an open-source discussion platform. Prior to ve…4.3
- CVE-2023-23617OpenMage LTS is an e-commerce platform. Versions prior to 19…7.5
- CVE-2023-23618Git for Windows is the Windows port of the revision control …7.8
- CVE-2023-23619Modelina is a library for generating data models based on in…8.8
- CVE-2023-23620Discourse is an open-source discussion platform. Prior to ve…5.3
- CVE-2023-23621Discourse is an open-source discussion platform. Prior to ve…7.5
- CVE-2023-23622Discourse is an open-source discussion platform. Prior to ve…4.3
- CVE-2023-23623Electron is a framework which lets you write cross-platform …9.8
- CVE-2023-23624Discourse is an open-source discussion platform. Prior to ve…5.3
- CVE-2023-23625go-unixfs is an implementation of a unix-like filesystem on …7.5
Are you affected by CVE-2023-2362?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
