Skip to content

Latest commit

 

History

History
24 lines (14 loc) · 909 Bytes

README.md

File metadata and controls

24 lines (14 loc) · 909 Bytes

CVE-2023-24398

WordPress EZP Coming Soon Page Plugin <= 1.0.7.3 is vulnerable to Cross Site Scripting (XSS)

Description

This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

Mitigation

Update the WordPress EZP Coming Soon Page plugin to the latest available version (at least 1.0.7.4).

Timeline

  • 29 January 2023: Reported to Patchstack
  • 30 January 2023: Vulnerability validated
  • 30 January 2023: Vulnerability fixed
  • 02 February 2023: Vulnerability disclosed

References