CVE-2023-5538
HIGHMpOperationLogs < 1.0.1 - Unauthenticated Stored Cross-Site Scripting via IP Request Headers
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-5538. PoCs published by juweihuitao.
AI-analyzed exploit summary The repository contains a README describing CVE-2023-5538, an unauthenticated stored XSS vulnerability in the WordPress plugin MpOperationLogs version <= 1.0.1. No exploit code is provided, only a brief description of the vulnerability.
Description
The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Exploits (1)
The repository contains a README describing CVE-2023-5538, an unauthenticated stored XSS vulnerability in the WordPress plugin MpOperationLogs version <= 1.0.1. No exploit code is provided, only a brief description of the vulnerability.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N