Security Advisory
CVE-2023-2122
6.1
MEDIUM
Vulnerability Description
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.
Published Date
August 16, 2023
Official Source
NIST NVD Advisory