VulnerabilityModified
CVE-2023-4294
The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created…
MEDIUM 6.1EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Affected
- kaizencoders/url shortify
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/1fc71fc7-861a-46cc-a147-1c7ece9a7776Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/1fc71fc7-861a-46cc-a147-1c7ece9a7776Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.