CVE-2023-0333
Published on: Not Yet Published
Last Modified on: 02/15/2023 04:09:00 PM UTC
Certain versions of Templatesnext Toolkit from Templatesnext contain the following vulnerability:
The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before using them to generate an HTML tag, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
- CVE-2023-0333 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Unknown - TemplatesNext ToolKit version < 3.2.9
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
TemplatesNext ToolKit < 3.2.9 - Contributor+ Stored XSS WordPress Security Vulnerability | web.archive.org text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Exploit/POC from Github
The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode attributes before usi…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Templatesnext | Templatesnext Toolkit | All | All | All | All |
- cpe:2.3:a:templatesnext:templatesnext_toolkit:*:*:*:*:*:wordpress:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-0333 | TemplatesNext ToolKit Plugin up to 3.2.8 on WordPress Shortcode cross site scripting A vulnerabilit… twitter.com/i/web/status/1… | 2023-01-20 09:50:35 |
![]() |
CVE-2023-0333 : The TemplatesNext ToolKit WordPress plugin before 3.2.9 does not validate some of its shortcode att… twitter.com/i/web/status/1… | 2023-02-13 15:21:31 |