cleantalk
Vulnerabilities and Security Researches

Custom 404 Pro, CVE-2023-2023

CVE, Research URL

CVE-2023-2023

Application

Custom 404 Pro

Published on
May 30, 2023
Research Description
The Custom 404 Pro WordPress plugin before 3.7.3 does not escape some URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting.
Affected versions
max 3.7.3.
Status
vulnerable