CVE-2023-6164 LOW

CVE-2023-6164: MainWP Dashboard <= 4.5.1.2 - Authenticated(Administrator+) CSS Injection

Vendor Mainwp
Product MainWP Dashboard: Self-hosted WordPress Management for Agencies
Weakness CWE-74
Published November 22, 2023
Last update April 8, 2026

CVSS base score

2.2/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary CSS values into the site tags.

Explanation of Vulnerability in Simple Terms

02Summary

MainWP Dashboard versions up to 4.5.1.2 contain an improper input validation flaw that allows high-privileged users to modify data integrity. The vulnerability requires network access and high administrative privileges to exploit. An attacker with admin-level access can alter site data, though the impact is limited to integrity and does not affect confidentiality or availability.

What an attacker can do

03Attacker Capabilities

Modify site data through improper input validation.

Potential impact on your site

04Site Impact

A malicious admin or compromised admin account could alter MainWP configuration or managed site data.

Conditions required to exploit

05Prerequisites

Attacker must have high-level administrative privileges on the MainWP Dashboard.

Key dates

06Disclosure timeline

November 22, 2023 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE