Vulnerabilities > CVE-2023-4798 - Unspecified vulnerability in Wpexperts User Avatar-Reloaded
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
LOW Integrity impact
LOW Availability impact
NONE Summary
The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |