Cyber Resilience

CVE-2023-0873

Kanbanwp Kanban Boards For Wordpress ≤ 2.5.21

Public PoC
Published
27 June 2023
Modified
21 November 2024
CVSS Score v3.1 4.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score 0.0055 43th percentile
Risk Priority 35 floored blend · peak EPSS

Summary

CVE-2023-0873 is a medium-severity an unspecified weakness vulnerability in Kanbanwp Kanban Boards For Wordpress. Its CVSS base score is 4.8 (Medium).

Operationally, ranked at the 43th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability Data

The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for…

more

example in multisite setup)

CWE(s)
None listed

Related Threats

CVEs Like This One

CVE-2023-40606Same product: Kanbanwp Kanban Boards For Wordpress
CVE-2023-23884Same product: Kanbanwp Kanban Boards For Wordpress
CVE-2025-3874Same product class: CMS core
CVE-2023-6558Same product class: CMS core
CVE-2026-47992Same product class: CMS core
CVE-2026-21292Same product class: CMS core
CVE-2026-60137Same product class: CMS core
CVE-2024-39405Same product class: CMS core
CVE-2023-23754Same product class: CMS core
CVE-2023-38218Same product class: CMS core

Affected Assets

kanbanwp
kanban boards for wordpress
≤ 2.5.21

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References