Files
CVEs-PoC/2023/CVE-2023-2113.md
T
2025-09-29 21:09:30 +02:00

864 B

CVE-2023-2113

Description

The Autoptimize WordPress plugin before 3.1.7 does not sanitise and escape the settings imported from a previous export, allowing high privileged users (such as an administrator) to inject arbitrary javascript into the admin panel, even when the unfiltered_html capability is disabled, such as in a multisite setup.

POC

Reference

Github