Record summary

CVE-2023-2009 has a selected CVSS score of 4.8 (medium); EIP currently links 1 Nuclei template.

Description

Plugin does not sanitize and escape the URL field in the Pretty Url WordPress plugin through 1.5.4 settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Pretty Url

Default status: affected

CVE ListThrough 1.5.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMPretty Url <= 1.5.4 - Cross-Site ScriptingCVSS 4.8

Plugin does not sanitize and escape the URL field in the plugin settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

Impact

High-privilege authenticated attackers can inject stored XSS through the URL field in plugin settings, potentially compromising other administrator accounts even when unfiltered_html capability is disabled in WordPress multisite setups.

Remediation

Update Pretty Url plugin to a version newer than 1.5.4 that properly sanitizes and escapes the URL field in plugin settings to prevent stored XSS attacks.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscve2023cvewordpresswpscanwp-pluginwpauthenticatedpretty-urlxsspretty_url_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:pretty_url_project:pretty_url:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2