CVE-2023-5911
Description
The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CWE
- (none)
Affected
- Unknown / WP Custom Cursors | WordPress Cursor Plugin — v=0 ≤3.2 [affected]
CVSS
- (none)
References
- https://wpscan.com/vulnerability/dde0767d-1dff-4261-adbe-1f3fdf2d9aae exploit, vdb-entry, technical-description
Source
cvelistV5-main/cves/2023/5xxx/CVE-2023-5911.json