CVE-2023-0157 is a stored cross-site scripting (XSS) vulnerability affecting the All-In-One Security (AIOS) WordPress plugin prior to version 5.1.5. An authenticated administrator can inject malicious JavaScript into log files, which then executes when another administrator views the plugin's admin page. This vulnerability has a CVSS score of 4.8 (Medium) and requires high privileges (PR:H) and user interaction (UI:R) for exploitation, with potential for low impact on confidentiality and integrity. Its EPSS score is 0.41771, indicating a higher than average exploitability likelihood compared to most CVEs. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion or media coverage has been observed for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.1.5CPE matchmatch criteria | cpe:2.3:a:updraftplus:all-in-one_security:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.