Record summary

CVE-2023-0602 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

Twittee Text Tweet

Default status: affected

CVE ListThrough 1.0.8affected

Nuclei templates

1
ProjectDiscoveryMEDIUMTwittee Text Tweet <= 1.0.8 - Cross-Site ScriptingCVSS 6.1

The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS attacks targeting administrators to happen.

Impact

Authenticated attackers targeting administrators can inject malicious JavaScript through POST values in administrative pages to steal admin session cookies and gain control of the WordPress site.

Remediation

Update Twittee Text Tweet plugin to a version newer than 1.0.8 that properly escapes POST values before outputting them in administrative pages.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscve2023cvewpscanxsswordpresswpwp-plugintwittee-text-tweetjohnniejodelljrvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:johnniejodelljr:twittee_text_tweet:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2