CVE-2023-7230

The illi Link Party! WordPress plugin through 1.0 does not sanitize and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:evanliewer:illi_link_party\!:*:*:*:*:*:wordpress:*:*

History

27 May 2025, 20:02

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/402e428b-f966-4a36-ace0-d0ded9410b1d/ - () https://wpscan.com/vulnerability/402e428b-f966-4a36-ace0-d0ded9410b1d/ - Exploit, Third Party Advisory
First Time Evanliewer
Evanliewer illi Link Party\!
CPE cpe:2.3:a:evanliewer:illi_link_party\!:*:*:*:*:*:wordpress:*:*
CWE CWE-79

16 May 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) El complemento illi Link Party! de WordPress, hasta la versión 1.0, no depura ni escapa algunos parámetros, lo que podría permitir que usuarios con un rol tan bajo como administrador realicen ataques de Cross-Site Scripting.

15 May 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 20:15

Updated : 2025-05-27 20:02


NVD link : CVE-2023-7230

Mitre link : CVE-2023-7230

CVE.ORG link : CVE-2023-7230


JSON object : View

Products Affected

evanliewer

  • illi_link_party\!
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')