
CVE-2023-0177 – Social Like Box and Page by WpDevArt < 0.8.41 - Contributor+ Stored XSS
https://notcve.org/view.php?id=CVE-2023-0177
23 Jan 2023 — The Social Like Box and Page by WpDevArt WordPress plugin before 0.8.41 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. The Social Like Box and Page by WpDevArt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 0.8.40 due to insufficient... • https://wpscan.com/vulnerability/712c2154-37f4-424c-ba3b-26ba6aa95bca • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-23972 – WordPress Social Like Box and Page by WpDevArt Plugin <= 0.8.39 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-23972
20 Jan 2023 — Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions. The Social Like Box and Page by WpDevArt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via select elements in versions up to, and including, 0.8.39 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages th... • https://patchstack.com/database/vulnerability/like-box/wordpress-social-like-box-and-page-by-wpdevart-plugin-0-8-39-cross-site-scripting-xss?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •