CVE-2023-0824
16.01.2024, 16:15
The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.
| Vendor | Product | Version |
|---|---|---|
| wpuserplus | userplus | 𝑥 ≤ 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration