CVE-2023-5738

All FrameworksWordPressCWE-OtherCVE-2023-5738

CVE-2023-5738

State: PUBLISHED · Published: 2023-11-27 · Updated: 2024-08-02 · Assigner: WPScan
Description
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/5xxx/CVE-2023-5738.json