CVE Database
/

CVE-2023-4294

Back to search

CVE-2023-4294

Published: Sep 11, 2023

Modified: May 2, 2025

PUBLISHED

Description

The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.

VendorProductVersions

Unknown

URL Shortify

affected
0 - < 1.7.6

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now