CVE-2023-0448
WP Helper Lite < 4.3 - Cross-Site Scripting
Record summary
CVE-2023-0448 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP Helper Lite Wordpress Plugin | CVE List | All versions prior to version 4.3 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWP Helper Lite < 4.3 - Cross-Site ScriptingCVSS 6.1
The WP Helper Lite WordPress plugin, in versions < 4.3, returns all GET parameters unsanitized in the response, resulting in a reflected cross-site scripting vulnerability.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Fixed in version 4.3 and above
Source: ProjectDiscovery