CVE-2023-34175
📛 CVE Title
WordPress Login Configurator Plugin <= 2.1 is vulnerable to Cross Site Scripting (XSS)
Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Patchstack
- CVSS severity
- HIGH
- CVSS score
- 7.1 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L- Effective score
- 7.1 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-79 - Reserved
- 2023-05-29
- Published
- 2023-08-30 15:39 UTC
- Last updated
- 2026-04-28 18:08 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/34xxx/CVE-2023-34175.json
- Linked Threat
- CVE-2023-34175 — Login Configurator <= 2.1 - Reflected Cross-Site Scripting
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-38275 - Assigner
- Patchstack
- Published
- Aug 30, 2023, 1:39:25 PM
- Updated
- Apr 28, 2026, 4:08:28 PM
- EUVD base score (CVSS 3.1)
-
7.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L - EUVD-reported EPSS
- 0.0900
- Vendors
- GrandSlambert
- Products
-
Login Configurator (n/a ≤2.1)
- Aliases
-
GHSA-r98x-6qxq-33f4
ENISA description: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GrandSlambert | Login Configurator |
n/a (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Indicators (1)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| cve |
CVE-2023-34175
|
no local data | 2026-06-06 15:04 UTC |
Remediations (17)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:www.hipaajournal.com
CISA Instructs Federal Agencies to Adopt Risk-Based Approach for Vulnerability Remediation Posted By Steve Alder on Jun 12, 2026 The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive (BOD 26-04) establishing new deadlines for vulnerability remediation for federal civilian agencies. Defenders have long been struggling to keep on top of patching ...
2026-06-15 20:11 UTC -
web:blog.qualys.com
Microsoft and Adobe Patch Tuesday, January 2026 Security Update Review Posted in Patch Tuesday, Vulnerabilities and Threat Research 11 Diksha Ojha December 10, 2025 - 7 min read
2026-06-15 20:11 UTC -
web:www.rapid7.com
Microsoft is addressing 67 vulnerabilities this June 2025 Patch Tuesday. Learn more about the findings in this Patch Tuesday.
2026-06-15 20:11 UTC -
web:github.com
CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes
2026-06-15 20:11 UTC -
web:www.computerworld.com
Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...
2026-06-15 20:11 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-06-15 20:11 UTC -
Wordfence remediation: Login ConfiguratorWordfence
No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
2026-06-06 15:04 UTC -
web:www.oracle.com
Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.
2026-05-22 06:39 UTC -
web:www.sentinelone.com
CVE - 2023 -38175 is a privilege escalation vulnerability in Microsoft Windows Defender. Learn about its impact, affected versions, and mitigation methods.
2026-05-22 06:39 UTC -
web:www.tenable.com
Oracle addresses 165 CVEs in its third quarterly update of 2025 with 309 patches, including nine critical updates.
2026-05-22 06:39 UTC -
web:support.esri.com
December 11, 2025: The 10.9.1 version of the Portal for ArcGIS Security 2025 Update 3 Patch has been updated to address 2 issues, BUG-000180365 and BUG-000179799. The 11.3 and 11.4 versions of the Portal for ArcGIS Security 2025 Update 3 Patch have been updated to address BUG-000180614.
2026-05-22 06:39 UTC -
web:blog.qualys.com
This Critical Patch Update for Oracle Communications Applications received 42 security patches. Out of these, 35 vulnerabilities can be exploited over a network without user credentials. CVE -2024-52046, CVE -2025-24813, and CVE -2024-40896 in different Oracle Communications Applications products have critical severity ratings.
2026-05-22 06:39 UTC -
web:dbsguru.com
Oracle Critical Database Patch ID for April 2025 along with enabled Download Link An Essential/Critical Patch Update could be a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and third-party elements enclosed in Oracle merchandise. These patches are sometimes additive, however, every informative describes only the protection ...
2026-05-22 06:39 UTC -
web:github.com
A new and improved community patch for BO3. . Contribute to shiversoftdev/t7patch development by creating an account on GitHub.
2026-05-22 06:39 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-22 06:39 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 06:39 UTC -
web:access.redhat.com
Learn about our open source products, services, and company. You are here
2026-05-22 06:39 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-34175.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-02T16:01:54.165Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"vdb-entry",
"x_transferred"
],
"url": "https://patchstack.com/database/vulnerability/login-configurator/wordpress-login-configurator-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2023-34175",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-09-24T19:18:39.758071Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-09-24T19:21:09.672Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "login-configurator",
"product": "Login Configurator",
"vendor": "GrandSlambert",
"versions": [
{
"lessThanOrEqual": "2.1",
"status": "affected",
"version": "n/a",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"user": "00000000-0000-4000-9000-000000000000",
"value": "thiennv (Patchstack Alliance)"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <=<span style=\"background-color: var(--wht);\">\u00a02.1 versions.</span>"
}
],
"value": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <=\u00a02.1 versions."
}
],
"impacts": [
{
"capecId": "CAPEC-591",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-591 Reflected XSS"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:08:28.479Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/vulnerability/login-configurator/wordpress-login-configurator-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
}
],
"source": {
"discovery": "EXTERNAL"
},
"title": "WordPress Login Configurator Plugin <= 2.1 is vulnerable to Cross Site Scripting (XSS)",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2023-34175",
"datePublished": "2023-08-30T13:39:25.858Z",
"dateReserved": "2023-05-29T13:52:11.723Z",
"dateUpdated": "2026-04-28T16:08:28.479Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}