Record summary

CVE-2023-1119 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jul 4, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 8, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

SrbTransLatin

Default status: unaffected

CVE ListBefore 2.4.1affected

WP-Optimize

Default status: unaffected

CVE ListBefore 3.2.13affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMWP-Optimize WordPress plugin < 3.2.13 - Cross-Site ScriptingCVSS 6.1

The WP-Optimize WordPress plugin before 3.2.13 and SrbTransLatin WordPress plugin before 2.4.1 are vulnerable to cross-site scripting due to a third-party library that improperly handles HTML character escaping.

Impact

Unauthenticated attackers can inject malicious JavaScript through search parameters due to improper HTML character escaping in a third-party library, enabling theft of WordPress user session cookies.

Remediation

Users are recommended to upgrade WP-Optimize to version 3.2.13 and SrbTransLatin to version 2.4.1 to mitigate the vulnerability.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2023wpwp-pluginwordpresswp-optimizexssvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wp-optimize:wp-optimize:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/wp-optimize"

Source: ProjectDiscovery

References

2