← back
CVE-2023-3746medium

ActivityPub for WordPress < 1.0.1 - Contributor+ Stored XSS

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
The ActivityPub WordPress plugin before 1.0.0 does not sanitize and escape some data from post content, which could allow contributor and above role to perform Stored Cross-Site Scripting attacks
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
Unknown · ActivityPub