Vulnerability Details CVE-2023-1840
The Sp*tify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.07 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 22.7%
CVSS Severity
CVSS v3 Score 4.4
Products affected by CVE-2023-1840
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:-
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.00
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.01
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.01.a
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.01.b
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.02
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.1
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.2
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.3
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.33
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.34
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.35
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.36
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.37
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.38
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.39
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.41
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.42
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.43
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.44
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.45
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:1.46
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:2.0
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:2.01
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:2.02
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:2.03
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:2.04
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:2.05
-
cpe:2.3:a:followmedarling:spotify-play-button-for-wordpress:2.06