Record summary

CVE-2023-40208 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aleksandar Urošević Stock Ticker plugin <= 3.23.3 versions.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 24, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 3.23.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMStock Ticker <= 3.23.2 - Cross-Site ScriptingCVSS 6.1

The Stock Ticker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in the ajax_stockticker_load function in versions up to, and including, 3.23.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Impact

Unauthenticated attackers can inject malicious JavaScript through the class parameter in the ajax_stockticker_load function to execute attacks when users interact with malicious links.

Remediation

Fixed in version 3.23.3

WeaknessesCWE-79
Authorstheamanrawat
Template tagscve2023cvewordpresswp-pluginwpscanwpstock-tickerxssurosevicvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:urosevic:stock_ticker:*:*:*:*:*:wordpress:*:*
Shodan: http.html:/wp-content/plugins/stock-ticker/
FOFA: body=/wp-content/plugins/stock-ticker/

Source: ProjectDiscovery

References

2