CVE-2023-2023
The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
- Affected products
- Custom 404 Pro
- Kunalnagar Custom 404 Pro
- < 3.7.3
- Fix
- Available
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.7% (76th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2023-05-30
CVE-2023-2023 at NVD
2 known exploits for CVE-2023-2023
Proof-of-concept code and exploit modules indexed by Sploitus