CVE-2023-5620
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
27/11/2023
Last modified:
02/12/2023
Description
The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:webpushr:web_push_notifications:*:*:*:*:*:wordpress:*:* | 4.35.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



