The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
References
Configurations
History
07 Nov 2023, 04:05
Type | Values Removed | Values Added |
---|---|---|
CWE |
18 Apr 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary | The YourChannel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | |
References |
|
11 Apr 2023, 14:51
Type | Values Removed | Values Added |
---|---|---|
First Time |
Plugin yourchannel
Plugin |
|
CPE | cpe:2.3:a:plugin:yourchannel:*:*:*:*:*:wordpress:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
References | (MISC) https://www.wordfence.com/threat-intel/vulnerabilities/id/a81d5615-0b96-4d89-a525-7e80a10a9317?source=cve - Third Party Advisory | |
References | (MISC) https://wordpress.org/plugins/yourchannel/ - Product |
05 Apr 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-05 14:15
Updated : 2023-11-07 04:05
NVD link : CVE-2023-1869
Mitre link : CVE-2023-1869
JSON object : View
Products Affected
plugin
- yourchannel
CWE
No CWE.