// For flags

CVE-2023-2362

Multiple Plugins from Wow-Company - Reflected XSS

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

*Credits: Erwan LR (WPScan), WPScan
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-04-28 CVE Reserved
  • 2023-05-22 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-08-02 First Exploit
  • 2024-11-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Wow-company
Search vendor "Wow-company"
Bubble Menu
Search vendor "Wow-company" for product "Bubble Menu"
< 3.0.4
Search vendor "Wow-company" for product "Bubble Menu" and version " < 3.0.4"
free, wordpress
Affected
Wow-company
Search vendor "Wow-company"
Button Generator
Search vendor "Wow-company" for product "Button Generator"
< 2.3.5
Search vendor "Wow-company" for product "Button Generator" and version " < 2.3.5"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Calculator-builder
Search vendor "Wow-company" for product "Calculator-builder"
< 1.5.1
Search vendor "Wow-company" for product "Calculator-builder" and version " < 1.5.1"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Counter Box
Search vendor "Wow-company" for product "Counter Box"
< 1.2.2
Search vendor "Wow-company" for product "Counter Box" and version " < 1.2.2"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Float Menu
Search vendor "Wow-company" for product "Float Menu"
< 5.0.2
Search vendor "Wow-company" for product "Float Menu" and version " < 5.0.2"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Floating Button
Search vendor "Wow-company" for product "Floating Button"
< 5.3.1
Search vendor "Wow-company" for product "Floating Button" and version " < 5.3.1"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Herd Effects
Search vendor "Wow-company" for product "Herd Effects"
< 5.2.2
Search vendor "Wow-company" for product "Herd Effects" and version " < 5.2.2"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Popup Box
Search vendor "Wow-company" for product "Popup Box"
< 2.2.2
Search vendor "Wow-company" for product "Popup Box" and version " < 2.2.2"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Side Menu Lite
Search vendor "Wow-company" for product "Side Menu Lite"
< 4.0.2
Search vendor "Wow-company" for product "Side Menu Lite" and version " < 4.0.2"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Sticky Buttons
Search vendor "Wow-company" for product "Sticky Buttons"
< 3.1.1
Search vendor "Wow-company" for product "Sticky Buttons" and version " < 3.1.1"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Wow Skype Buttons
Search vendor "Wow-company" for product "Wow Skype Buttons"
< 4.0.2
Search vendor "Wow-company" for product "Wow Skype Buttons" and version " < 4.0.2"
wordpress
Affected
Wow-company
Search vendor "Wow-company"
Wp Coder
Search vendor "Wow-company" for product "Wp Coder"
< 2.5.6
Search vendor "Wow-company" for product "Wp Coder" and version " < 2.5.6"
wordpress
Affected