‘WordPress Core plugin for Kitestudio themes’ (versions <= 2.3.0) Reflected cross-site scripting (XSS) vulnerability

Details

Reflected cross-site scripting (XSS) vulnerability discovered in the WordPressCore plugin for the Kitestudio theme (version <= 2.3.0).

solution

Update the WordPressCore plugin for the Kitestudio theme to the latest version available (at least 2.3.1).

Sources.

core plugin for kitestudio themes
Useful plugin that extends functionality of Kitestudio Themes by adding woocommerce shortcodes and widgets

脆弱性情報を受け取る