The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Metrics
Affected Vendors & Products
References
History
Mon, 09 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Antonpug
Antonpug better Flow Button For Jetpack |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:antonpug:better_flow_button_for_jetpack:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Antonpug
Antonpug better Flow Button For Jetpack |
Tue, 20 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 15 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Better Follow Button for Jetpack WordPress plugin through 8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
Title | Better Follow Button for Jetpack <= 8.0 - Admin+ Stored XSS | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-05-15T20:09:23.563Z
Updated: 2025-05-20T15:05:42.429Z
Reserved: 2023-12-29T03:30:20.560Z
Link: CVE-2023-7168

Updated: 2025-05-20T15:05:31.818Z

Status : Analyzed
Published: 2025-05-15T20:15:30.120
Modified: 2025-06-09T18:54:07.350
Link: CVE-2023-7168

No data.