CVE-2023-5057

CVE-2023-5057: ActivityPub for WordPress < 1.0.0 - Contributor+ Stored XSS

Vendor Unknown
Product ActivityPub
Published October 16, 2023
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

The ActivityPub WordPress plugin before 1.0.0 does not escape user metadata before outputting them in mentions, which could allow users with a role of Contributor and above to perform Stored XSS attacks

Key dates

02Disclosure timeline

October 16, 2023 CVE published
August 2, 2024 Record updated