CVE-2023-47844 is a Reflected Cross-site Scripting (XSS) vulnerability found in Lim Kai Yang's Grab & Save plugin, affecting versions up to and including 1.0.4. This vulnerability allows an attacker to inject malicious scripts into web pages due to improper neutralization of user input. The vulnerability has a CVSS score of 6.1 (Medium), indicating that it can be exploited remotely with low attack complexity, requiring user interaction to succeed. A successful attack could lead to limited confidentiality and integrity impacts, such as session hijacking or defacement. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. The vulnerability has received minimal community discussion and media coverage, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.4CPE matchmatch criteria | cpe:2.3:a:neobie:grab_\&_save:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.