Skip to content

Latest commit

 

History

History

CVE-2023-24398

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 

CVE-2023-24398

WordPress EZP Coming Soon Page Plugin <= 1.0.7.3 is vulnerable to Cross Site Scripting (XSS)

Description

This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

Mitigation

Update the WordPress EZP Coming Soon Page plugin to the latest available version (at least 1.0.7.4).

Timeline

  • 29 January 2023: Reported to Patchstack
  • 30 January 2023: Vulnerability validated
  • 30 January 2023: Vulnerability fixed
  • 02 February 2023: Vulnerability disclosed

References