The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
References
Configurations
History
07 Nov 2023, 04:05
Type | Values Removed | Values Added |
---|---|---|
CWE |
18 Apr 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. |
11 Apr 2023, 14:51
Type | Values Removed | Values Added |
---|---|---|
First Time |
Plugin yourchannel
Plugin |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
CPE | cpe:2.3:a:plugin:yourchannel:*:*:*:*:*:wordpress:*:* | |
References | (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/a81d5615-0b96-4d89-a525-7e80a10a9317?source=cve - Third Party Advisory | |
References | (MISC) https://wordpress.org/plugins/yourchannel/ - Product |
05 Apr 2023, 17:35
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-05 14:15
Updated : 2023-12-10 15:01
NVD link : CVE-2023-1869
Mitre link : CVE-2023-1869
CVE.ORG link : CVE-2023-1869
JSON object : View
Products Affected
plugin
- yourchannel
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')