Unrated severityNVD Advisory· Published Jul 17, 2023· Updated Feb 13, 2025
Login Configurator <= 2.1 - Reflected Cross-Site Scripting
CVE-2023-1893
Description
The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.
Affected products
1- Range: <=2.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- wpscan.com/vulnerability/dbe6cf09-971f-42e9-b744-9339454168c7mitreexploitvdb-entrytechnical-description
- packetstormsecurity.com/files/173723/WordPress-Login-Configurator-2.1-Cross-Site-Scripting.htmlmitre
News mentions
0No linked articles in our index yet.