Record summary

CVE-2023-2624 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as administrator

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 27, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

KiviCare

Default status: unaffected

CVE ListBefore 3.2.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMKiviCare WordPress Plugin - Cross-Site ScriptingCVSS 6.1

The KiviCare WordPress plugin before 3.2.1 does not sanitise and escape the 'filterType' parameter, leading to Reflected Cross-Site Scripting.

Impact

Successful exploitation could allow an attacker to execute malicious scripts in the context of the victim's browser.

Remediation

Update to the latest version of the KiviCare WordPress Plugin to mitigate the XSS vulnerability.

Authorsritikchaddha
Template tagscvecve2023kivicarewpwp-pluginwordpresswpscanauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:iqonic:kivicare:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3