CVE-2023-0175
20.03.2023, 16:15
The Responsive Clients Logo Gallery Plugin for WordPress plugin through 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.Enginsight
| Vendor | Product | Version |
|---|---|---|
| accesspressthemes | smart_logo_showcase_lite | 1.0.0 |
| accesspressthemes | smart_logo_showcase_lite | 1.0.1 |
| accesspressthemes | smart_logo_showcase_lite | 1.0.2 |
| accesspressthemes | smart_logo_showcase_lite | 1.0.3 |
| accesspressthemes | smart_logo_showcase_lite | 1.0.4 |
| accesspressthemes | smart_logo_showcase_lite | 1.0.5 |
| accesspressthemes | smart_logo_showcase_lite | 1.0.6 |
| accesspressthemes | smart_logo_showcase_lite | 1.0.7 |
| accesspressthemes | smart_logo_showcase_lite | 1.0.8 |
| accesspressthemes | smart_logo_showcase_lite | 1.0.9 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.0 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.1 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.2 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.3 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.4 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.5 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.6 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.7 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.8 |
| accesspressthemes | smart_logo_showcase_lite | 1.1.9 |
𝑥
= Vulnerable software versions