CVE-2023-6987 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 2.6.5 of the String locator plugin for WordPress. This flaw, stemming from insufficient input sanitization and output escaping of the 'sql-column' parameter, allows unauthenticated attackers to inject arbitrary web scripts. Exploitation requires WP_DEBUG to be enabled and relies on user interaction, such as clicking a malicious link. The vulnerability carries a CVSS score of 6.1 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and leading to low impact on confidentiality and integrity. While the EPSS score is low, suggesting limited real-world exploitability, the FAUCET Risk Score is 34/100. There is currently no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, aligning with typical patterns for the vast majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 2.6.5CPE match | cpe:2.3:a:instawp:string_locator:*:*:*:*:*:wordpress:*:* | ||
< 2.6.6CPE matchmatch criteria | cpe:2.3:a:instawp:string_locator:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.