Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Katie Seaborn Zotpress plugin <= 7.3.3 versions.
Exploits (1)
References (2)
Core 2
Core References
Third Party Advisory vdb-entry
https://patchstack.com/database/vulnerability/zotpress/wordpress-zotpress-plugin-7-3-3-cross-site-scripting-xss-vulnerability?_s_id=cve
Various Sources technical-description
https://lourcode.kr/posts/CVE-2023-32961-Analysis/
Scores
CVSS v3
7.1
EPSS
0.0470
EPSS Percentile
89.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
Katie Seaborn/Zotpress
< 7.3.3
zotpress_project/zotpress
< 7.3.3
Published
Jun 12, 2023
Tracked Since
Feb 18, 2026