CVE Database
/

CVE-2023-4798

Back to search

CVE-2023-4798

Published: Oct 16, 2023

Modified: Aug 2, 2024

PUBLISHED

Description

The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.

VendorProductVersions

Unknown

User Avatar

affected
0 - < 1.2.2

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now