CVE-2023-1893
MEDIUM 6.1EPSS 0.7%
The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.
- CVSS v3.1
- 6.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS
- 0.72% chance of exploitation in the next 30 days, 51th percentile
- Nuclei
- medium · CWE-79
- Published
- 2023-07-17
- Updated
- 2025-02-13
Proof-of-concept exploits (2)
- http://packetstormsecurity.com/files/173723/WordPress-Login-Configurator-2.1-Cross-Site-S…
- https://wpscan.com/vulnerability/dbe6cf09-971f-42e9-b744-9339454168c7