vendor:
Neon Text Plugin
by:
Eren Car
4.1
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Neon Text Plugin
Affected Version From: 1
Affected Version To: 45292
Patch Exists: YES
Related CWE: CVE-2023-5817
CPE: a:neon_text:neon_text:1.0
Platforms Tested: Debian / WordPress 6.4.1
2023
WordPress Plugin Neon Text <= 1.1 - Stored Cross Site Scripting (XSS)
The Neon Text plugin for WordPress versions 1.1 and below is prone to Stored Cross-Site Scripting vulnerability through the neontext_box shortcode.
Mitigation:
Update to version 1.1.1 or later to mitigate this vulnerability by sanitizing user inputs and implementing output encoding.