CVE-2023-4294
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
11/09/2023
Last modified:
02/05/2025
Description
The URL Shortify WordPress plugin before 1.7.6 does not properly escape the value of the referer header, thus allowing an unauthenticated attacker to inject malicious javascript that will trigger in the plugins admin panel with statistics of the created short link.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:kaizencoders:url_shortify:*:*:*:*:*:wordpress:*:* | 1.7.6 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



