CVE-2023-47790

HIGH

Poporon Pz-LinkCard <= 2.4.8 - Cross-Site Request Forgery leading to Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in Poporon Pz-LinkCard plugin <= 2.4.8 versions.

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 10.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

Details

CWE
CWE-352 CWE-79
Status published
Products (2)
Poporon/Pz-LinkCard < 2.4.8
popozure/pz-linkcard < 2.4.8
Published Nov 23, 2023
Tracked Since Feb 18, 2026