CVE-2023-47524 MEDIUM

CVE-2023-47524: WordPress CodeBard's Patron Button and Widgets for Patreon Plugin <= 2.1.9 is vulnerable to Cross Site Scripting (XSS)

Vendor Codebard
Product CodeBard's Patron Button and Widgets for Patreon
Weakness CWE-79 · XSS
Published November 14, 2023
Last update April 28, 2026

CVSS base score

5.8/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability (requires PHP 8.x) in CodeBard CodeBard's Patron Button and Widgets for Patreon plugin <= 2.1.9 versions.

Explanation of Vulnerability in Simple Terms

02Summary

CodeBard's Patron Button and Widgets for Patreon versions up to 2.1.9 contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in visitors' browsers when they interact with the widget. The vulnerability requires user interaction and affects the integrity and confidentiality of site visitors. Update to a version newer than 2.1.9 to resolve this issue.

What an attacker can do

03Attacker Capabilities

Inject malicious scripts that run in visitors' browsers when they interact with the Patreon widget.

Potential impact on your site

04Site Impact

Visitors' browsers can be compromised when they use your Patreon widget, potentially stealing data or redirecting them.

Conditions required to exploit

05Prerequisites

Visitor must interact with the affected widget; no authentication required.

Key dates

06Disclosure timeline

November 14, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE