CVE-2023-0175
20.03.2023, 16:15
The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.Enginsight
Vendor | Product | Version |
---|---|---|
accesspressthemes | smart_logo_showcase_lite | 1.0.0 |
accesspressthemes | smart_logo_showcase_lite | 1.0.1 |
accesspressthemes | smart_logo_showcase_lite | 1.0.2 |
accesspressthemes | smart_logo_showcase_lite | 1.0.3 |
accesspressthemes | smart_logo_showcase_lite | 1.0.4 |
accesspressthemes | smart_logo_showcase_lite | 1.0.5 |
accesspressthemes | smart_logo_showcase_lite | 1.0.6 |
accesspressthemes | smart_logo_showcase_lite | 1.0.7 |
accesspressthemes | smart_logo_showcase_lite | 1.0.8 |
accesspressthemes | smart_logo_showcase_lite | 1.0.9 |
accesspressthemes | smart_logo_showcase_lite | 1.1.0 |
accesspressthemes | smart_logo_showcase_lite | 1.1.1 |
accesspressthemes | smart_logo_showcase_lite | 1.1.2 |
accesspressthemes | smart_logo_showcase_lite | 1.1.3 |
accesspressthemes | smart_logo_showcase_lite | 1.1.4 |
accesspressthemes | smart_logo_showcase_lite | 1.1.5 |
accesspressthemes | smart_logo_showcase_lite | 1.1.6 |
accesspressthemes | smart_logo_showcase_lite | 1.1.7 |
accesspressthemes | smart_logo_showcase_lite | 1.1.8 |
accesspressthemes | smart_logo_showcase_lite | 1.1.9 |
𝑥
= Vulnerable software versions