CVE-2023-0418

CVE-2023-0418: Video Central for WordPress <= 1.3.0 - Contributor+ Stored XSS

Vendor Unknown
Product Video Central for WordPress
Published April 24, 2023
Last update February 4, 2025

CVSS base score

What the vulnerability does

01Description

The Video Central for WordPress plugin through 1.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Key dates

02Disclosure timeline

April 24, 2023 CVE published
February 4, 2025 Record updated