Record summary

CVE-2023-30868 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 9, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 1.6.7affected

Proofs of concept

1

Catalogued exploits

ExploitDBTree Page View Plugin 1.6.7 - Cross Site Scripting (XSS)ExploitDB exploitby LEE SE HYOUNGNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMTree Page View Plugin < 1.6.7 - Cross-Site ScriptingCVSS 6.1

The CMS Tree Page View plugin for WordPress has a Reflected Cross-Site Scripting vulnerability up to version 1.6.7. This is due to the post_type parameter not properly escaping user input. As a result, users with administrator privileges or higher can inject JavaScript code that will execute whenever accessed.

Impact

Authenticated high-privilege attackers (admin) can inject malicious JavaScript through the post_type parameter to compromise other administrator accounts and gain persistent access to the WordPress site.

Remediation

Update CMS Tree Page View plugin to version 1.6.7 or later that properly escapes the post_type parameter in the admin interface to prevent reflected XSS attacks.

WeaknessesCWE-79
Authorsr3Y3r53
Template tagscve2023cvewpscanpacketstormxsswpwordpressauthenticatedexploitdbcms_tree_page_view_projectvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:cms_tree_page_view_project:cms_tree_page_view:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3