Record summary

CVE-2023-1546 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 30, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

MyCryptoCheckout

Default status: unaffected

CVE ListBefore 2.124affected

Nuclei templates

1
ProjectDiscoveryMEDIUMMyCryptoCheckout < 2.124 - Cross-Site ScriptingCVSS 6.1

The MyCryptoCheckout WordPress plugin before 2.124 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Fixed in version 2.124

WeaknessesCWE-79
AuthorsHarsh
Template tagscvecve2023wordpresswpwp-pluginxsswpscanauthenticatedplainviewpluginsvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:plainviewplugins:mycryptocheckout:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2