CVE-2023-1119
Multiple Plugins - Cross-Site Scripting From Third-party Library
Record summary
CVE-2023-1119 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The WP-Optimize WordPress plugin before 3.2.13, SrbTransLatin WordPress plugin before 2.4.1 use a third-party library that removes the escaping on some HTML characters, leading to a cross-site scripting vulnerability.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jul 4, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 8, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
SrbTransLatinDefault status: unaffected | CVE List | Before 2.4.1 | affected |
WP-OptimizeDefault status: unaffected | CVE List | Before 3.2.13 | affected |
srbtranslatinBrowse srbtranslatin_project / srbtranslatin | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWP-Optimize WordPress plugin < 3.2.13 - Cross-Site ScriptingCVSS 6.1
The WP-Optimize WordPress plugin before 3.2.13 and SrbTransLatin WordPress plugin before 2.4.1 are vulnerable to cross-site scripting due to a third-party library that improperly handles HTML character escaping.
Impact
Unauthenticated attackers can inject malicious JavaScript through search parameters due to improper HTML character escaping in a third-party library, enabling theft of WordPress user session cookies.
Remediation
Users are recommended to upgrade WP-Optimize to version 3.2.13 and SrbTransLatin to version 2.4.1 to mitigate the vulnerability.
Source: ProjectDiscovery