← back
CVE-2023-6164

MainWP Dashboard <= 4.5.1.2 - Authenticated(Administrator+) CSS Injection

CVSS 2.2 LOWEPSS 0.4%CWE-74
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 2.2EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
22 Nov 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The MainWP Dashboard – WordPress Manager for Multiple Websites Maintenance plugin for WordPress is vulnerable to CSS Injection via the ‘newColor’ parameter in all versions up to, and including, 4.5.1.2 due to insufficient input sanitization. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary CSS values into the site tags.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →