CVE-2023-6141
08.01.2024, 19:15
The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks.
Vendor | Product | Version |
---|---|---|
g5plus | essential_real_estate | 𝑥 < 4.4.0 |
𝑥
= Vulnerable software versions