Record summary

CVE-2023-47684 has a selected CVSS score of 7.1 (high); EIP currently links 1 Nuclei template.

Description

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 3.1.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMEssential Grid <= 3.1.0 - Cross-Site ScriptingCVSS 6.1

Unauthenticated Reflected Cross-Site Scripting (XSS) vulnerability in ThemePunch OHG Essential Grid plugin <= 3.1.0 versions.

Impact

Unauthenticated attackers can inject malicious JavaScript via reflected XSS, potentially stealing user session cookies or performing actions on behalf of users.

Remediation

Update Essential Grid plugin to version 3.1.1 or later.

WeaknessesCWE-79
Authors0xpugal
Template tagscvecve2023wordpresswpxsswp-themeessential-gridthemepunchvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:themepunch:essential_grid:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2