Record summary

CVE-2023-27922 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Cross-site scripting vulnerability in Newsletter versions prior to 7.6.9 allows a remote unauthenticated attacker to inject an arbitrary script.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 17, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE Listversions prior to 7.6.9affected

Nuclei templates

1
ProjectDiscoveryMEDIUMNewsletter < 7.6.9 - Cross-Site ScriptingCVSS 6.1

The plugin does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators

Impact

Authenticated attackers can exploit reflected XSS through unescaped URL parameters to target high-privilege users like administrators, potentially stealing admin session cookies and hijacking WordPress sites using the Newsletter plugin.

Remediation

Update Newsletter plugin to version 7.6.9 or later that properly escapes generated URLs before outputting them in HTML attributes.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscve2023cvewpscanwordpresswpwp-pluginxssnewsletterauthenticatedthenewsletterpluginvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:thenewsletterplugin:newsletter:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/newsletter/
FOFA: body=/wp-content/plugins/newsletter/

Source: ProjectDiscovery

References

3