CVE-2023-0873
Kanbanwp Kanban Boards For Wordpress ≤ 2.5.21
Raw vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:NSummary
CVE-2023-0873 is a medium-severity an unspecified weakness vulnerability in Kanbanwp Kanban Boards For Wordpress. Its CVSS base score is 4.8 (Medium).
Operationally, ranked at the 43th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-12864
Vulnerability Data
The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for…
more
example in multisite setup)
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.