« Volver al listado

CVE-2023-4798

Estado: ModificadaMedia (5.4)—

The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-4798",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "User Avatar",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.2.2",
              "versionType": "custom"
            }
          ],
          "collectionURL": "https://wordpress.org/plugins",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-10-16T20:15:16.500",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/273a95bf-39fe-4ba7-bc14-9527acfd9f42",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/273a95bf-39fe-4ba7-bc14-9527acfd9f42",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "descriptions": [
    {
      "lang": "en",
      "value": "The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks."
    },
    {
      "lang": "es",
      "value": "El complemento User Avatar de WordPress anterior a 1.2.2 no sanitiza ni escapa adecuadamente a algunos de sus atributos de shortcodes, lo que podría permitir a usuarios con privilegios relativamente bajos, como los contribuyentes, realizar ataques XSS almacenados."
    }
  ],
  "lastModified": "2026-06-17T06:38:36.290",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wpexperts:user_avatar-reloaded:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FF0EC19-45C4-4033-9544-A47EB2B350C5",
              "versionEndExcluding": "1.2.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}