CVE-2023-46199 MEDIUM

CVE-2023-46199: WordPress Triberr Plugin <= 4.1.1 is vulnerable to Cross Site Scripting (XSS)

Vendor Triberr
Product Triberr
Weakness CWE-79 · XSS
Published October 27, 2023
Last update April 28, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Triberr plugin <= 4.1.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Triberr versions up to 4.1.1 contain a cross-site scripting (XSS) vulnerability that allows an authenticated attacker with high privileges to inject malicious scripts. The vulnerability requires user interaction—typically a victim clicking a crafted link or visiting a malicious page. The impact is limited to low-severity data exposure and site modification.

What an attacker can do

03Attacker Capabilities

Inject malicious scripts that execute in a victim's browser and steal data or modify page content.

Potential impact on your site

04Site Impact

A privileged attacker can deface content or steal session data from other users who click their links.

Conditions required to exploit

05Prerequisites

Attacker must have high-level account privileges and trick a user into clicking a malicious link or visiting a crafted page.

Key dates

06Disclosure timeline

October 27, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE