vendor:
Neon Text
by:
Eren Car
4.1
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Neon Text
Affected Version From: 1
Affected Version To: 1.1
Patch Exists: YES
Related CWE: CVE-2023-5817
CPE: a:wordpress:neon_text:1.0
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=101572, https://www.infosecmatter.com/nessus-plugin-library/?id=71171, https://www.infosecmatter.com/nessus-plugin-library/?id=71037, https://www.infosecmatter.com/nessus-plugin-library/?id=70472, https://www.infosecmatter.com/nessus-plugin-library/?id=86001, https://www.infosecmatter.com/nessus-plugin-library/?id=86601, https://www.infosecmatter.com/nessus-plugin-library/?id=85987, https://www.infosecmatter.com/nessus-plugin-library/?id=73969, https://www.infosecmatter.com/nessus-plugin-library/?id=86270, https://www.infosecmatter.com/nessus-plugin-library/?id=58001
Platforms Tested: Debian / WordPress 6.4.1
2023
WordPress Plugin Neon Text <= 1.1 - Stored Cross Site Scripting (XSS)
The Neon Text plugin for WordPress version 1.1 and below is prone to Stored Cross-Site Scripting (XSS) vulnerability through the neontext_box shortcode.
Mitigation:
To mitigate this vulnerability, users should update to the latest version of the Neon Text plugin (1.2 or higher) where the issue has been patched.