VYPR
High severity7.1NVD Advisory· Published Jul 25, 2023· Updated Jun 17, 2026

CVE-2023-36502

CVE-2023-36502

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon plugin <= 1.3.2 versions.

Affected products

3
  • Crafthemes/Balkoncpe-rescue2 versions
    n/a+ 1 more
    • (no CPE)range: n/a
    • cpe:2.3:a:cththemes:balkon:*:*:*:*:*:wordpress:*:*range: <=1.3.2
  • WordPress/Balkonllm-fuzzy
    Range: <=1.3.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.