CVE-2023-0423

CVE-2023-0423: WordPress Amazon S3 Plugin < 1.6 - Reflected XSS

Vendor Unknown
Product WordPress Amazon S3 Plugin
Published April 10, 2023
Last update February 11, 2025

CVSS base score

What the vulnerability does

01Description

The WordPress Amazon S3 Plugin WordPress plugin before 1.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Key dates

02Disclosure timeline

April 10, 2023 CVE published
February 11, 2025 Record updated