VYPR
Unrated severityNVD Advisory· Published Jul 17, 2023· Updated Feb 13, 2025

Login Configurator <= 2.1 - Reflected Cross-Site Scripting

CVE-2023-1893

Description

The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.