CVE-2023-23735
WordPress Spectra – WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email HTML Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Brainstorm Force Spectra allows Code Injection.This issue affects Spectra: from n/a through 2.3.0.
La neutralización inadecuada de etiquetas HTML relacionadas con scripts en una vulnerabilidad de página web (XSS básico) en Brainstorm Force Spectra permite la inyección de código. Este problema afecta a Spectra: desde n/a hasta 2.3.0.
The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to HTML injection via Email in versions up to, and including, 2.3.1. This is due to insufficient input validation and output escaping of content being sent via email. This makes it possible for unauthenticated attackers to send emails to unsuspecting victims with content containing HTML.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-01-17 CVE Reserved
- 2023-01-23 CVE Published
- 2024-06-04 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CAPEC
- CAPEC-242: Code Injection
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ultimate Addons For Gutenberg Search vendor "Ultimate Addons For Gutenberg" | Ultimate Addons For Gutenberg Search vendor "Ultimate Addons For Gutenberg" for product "Ultimate Addons For Gutenberg" | >= 0.0.0 <= 2.3.1 Search vendor "Ultimate Addons For Gutenberg" for product "Ultimate Addons For Gutenberg" and version " >= 0.0.0 <= 2.3.1" | en |
Affected
|