Cyber Resilience

CVE-2023-2362

MediumPublic PoC

Published: 12 June 2023

Published
12 June 2023
Modified
05 May 2025
KEV Added
Patch
CVSS Score v3.1 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score 0.0015 35.0th percentile
Risk Priority 12 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2023-2362 is a medium-severity an unspecified weakness vulnerability in Wow-Company Bubble Menu. Its CVSS base score is 6.1 (Medium).

Operationally, ranked at the 35.0th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability details

The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress…

more

plugin before 5.2.2, Popup Box WordPress plugin before 2.2.2, Side Menu Lite WordPress plugin before 4.0.2, Sticky Buttons WordPress plugin before 3.1.1, Wow Skype Buttons WordPress plugin before 4.0.2, WP Coder WordPress plugin before 2.5.6 do not escape the page parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

CWE(s)
None listed

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

wow-company
bubble menu
≤ 3.0.4
wow-company
button generator
≤ 2.3.5
wow-company
calculator-builder
≤ 1.5.1
wow-company
counter box
≤ 1.2.2
wow-company
float menu
≤ 5.0.2
wow-company
floating button
≤ 5.3.1
wow-company
herd effects
≤ 5.2.2
wow-company
popup box
≤ 2.2.2
wow-company
side menu lite
≤ 4.0.2
wow-company
sticky buttons
≤ 3.1.1
+2 more product configuration(s) — see NVD for full list

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References