{ "id": "CVE-2023-1982", "sourceIdentifier": "contact@wpscan.com", "published": "2023-08-30T15:15:08.477", "lastModified": "2023-08-31T10:02:10.690", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "The Front Editor WordPress plugin through 4.0.4 does not sanitize and escape some of its form settings, which could allow high-privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)" } ], "metrics": {}, "weaknesses": [ { "source": "contact@wpscan.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "references": [ { "url": "https://wpscan.com/vulnerability/51987966-8007-4e12-bc2e-997b92054739", "source": "contact@wpscan.com" } ] }