s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2023-34175

📛 CVE Title

WordPress Login Configurator Plugin <= 2.1 is vulnerable to Cross Site Scripting (XSS)

Description

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.

Overview

State
PUBLISHED
Assigner (CNA)
Patchstack
CVSS severity
HIGH
CVSS score
CVSS 7.1 / 10 7.1 7.1 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Effective score
7.1 / 10 HIGH source: CNA overview
CWE(s)
CWE-79
Reserved
2023-05-29
Published
2023-08-30 15:39 UTC
Last updated
2026-04-28 18:08 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/34xxx/CVE-2023-34175.json
Linked Threat
CVE-2023-34175 — Login Configurator <= 2.1 - Reflected Cross-Site Scripting

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2023-38275
Assigner
Patchstack
Published
Aug 30, 2023, 1:39:25 PM
Updated
Apr 28, 2026, 4:08:28 PM
EUVD base score (CVSS 3.1)
7.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EUVD-reported EPSS
0.0900
Vendors
GrandSlambert
Products
Login Configurator (n/a ≤2.1)
Aliases
GHSA-r98x-6qxq-33f4

ENISA description: Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions.

EUVD references (1)

Affected products (1)

VendorProductVersionsPlatforms
GrandSlambert Login Configurator n/a (affected)

Vendor references (1)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Indicators (1)

IOCs linked to the auto-promoted Threat row.

TypeValueVirusTotalAttached
cve CVE-2023-34175 no local data 2026-06-06 15:04 UTC

Flagged vendors

    Remediations (17)

    Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

    • web:www.hipaajournal.com

      CISA Instructs Federal Agencies to Adopt Risk-Based Approach for Vulnerability Remediation Posted By Steve Alder on Jun 12, 2026 The Cybersecurity and Infrastructure Security Agency (CISA) has issued a Binding Operational Directive (BOD 26-04) establishing new deadlines for vulnerability remediation for federal civilian agencies. Defenders have long been struggling to keep on top of patching ...

      2026-06-15 20:11 UTC
    • web:blog.qualys.com

      Microsoft and Adobe Patch Tuesday, January 2026 Security Update Review Posted in Patch Tuesday, Vulnerabilities and Threat Research 11 Diksha Ojha December 10, 2025 - 7 min read

      2026-06-15 20:11 UTC
    • web:www.rapid7.com

      Microsoft is addressing 67 vulnerabilities this June 2025 Patch Tuesday. Learn more about the findings in this Patch Tuesday.

      2026-06-15 20:11 UTC
    • web:github.com

      CVEfixes: Automated Collection of Vulnerabilities and Their Fixes from Open-Source Software - secureIT-project/CVEfixes

      2026-06-15 20:11 UTC
    • web:www.computerworld.com

      Microsoft says it is considering a patch for a zero-day vulnerability, dubbed YellowKey, that allows attackers with access to a Windows device to bypass Bitlocker encryption protection and read ...

      2026-06-15 20:11 UTC
    • web:zecurit.com

      Get the complete breakdown of Microsoft's June 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

      2026-06-15 20:11 UTC
    • Wordfence remediation: Login Configurator
      Wordfence

      No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

      2026-06-06 15:04 UTC
    • web:www.oracle.com

      Critical Security Patch Updates Critical Security Patch Updates provide security patches for supported Oracle on-premises products. A Critical Security Patch Update provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption.

      2026-05-22 06:39 UTC
    • web:www.sentinelone.com

      CVE - 2023 -38175 is a privilege escalation vulnerability in Microsoft Windows Defender. Learn about its impact, affected versions, and mitigation methods.

      2026-05-22 06:39 UTC
    • web:www.tenable.com

      Oracle addresses 165 CVEs in its third quarterly update of 2025 with 309 patches, including nine critical updates.

      2026-05-22 06:39 UTC
    • web:support.esri.com

      December 11, 2025: The 10.9.1 version of the Portal for ArcGIS Security 2025 Update 3 Patch has been updated to address 2 issues, BUG-000180365 and BUG-000179799. The 11.3 and 11.4 versions of the Portal for ArcGIS Security 2025 Update 3 Patch have been updated to address BUG-000180614.

      2026-05-22 06:39 UTC
    • web:blog.qualys.com

      This Critical Patch Update for Oracle Communications Applications received 42 security patches. Out of these, 35 vulnerabilities can be exploited over a network without user credentials. CVE -2024-52046, CVE -2025-24813, and CVE -2024-40896 in different Oracle Communications Applications products have critical severity ratings.

      2026-05-22 06:39 UTC
    • web:dbsguru.com

      Oracle Critical Database Patch ID for April 2025 along with enabled Download Link An Essential/Critical Patch Update could be a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and third-party elements enclosed in Oracle merchandise. These patches are sometimes additive, however, every informative describes only the protection ...

      2026-05-22 06:39 UTC
    • web:github.com

      A new and improved community patch for BO3. . Contribute to shiversoftdev/t7patch development by creating an account on GitHub.

      2026-05-22 06:39 UTC
    • web:nvd.nist.gov

      An official website of the United States government Here's how you know

      2026-05-22 06:39 UTC
    • web:portal.msrc.microsoft.com

      The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

      2026-05-22 06:39 UTC
    • web:access.redhat.com

      Learn about our open source products, services, and company. You are here

      2026-05-22 06:39 UTC

    AI Forensic Analysis

    Only Available for Registered Users. Sign in to view.

    Raw JSON

    The full cvelistV5 record. Download as CVE-2023-34175.json.

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T16:01:54.165Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_transferred"
                ],
                "url": "https://patchstack.com/database/vulnerability/login-configurator/wordpress-login-configurator-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2023-34175",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-24T19:18:39.758071Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-24T19:21:09.672Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://wordpress.org/plugins",
              "defaultStatus": "unaffected",
              "packageName": "login-configurator",
              "product": "Login Configurator",
              "vendor": "GrandSlambert",
              "versions": [
                {
                  "lessThanOrEqual": "2.1",
                  "status": "affected",
                  "version": "n/a",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "thiennv (Patchstack Alliance)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <=<span style=\"background-color: var(--wht);\">\u00a02.1 versions.</span>"
                }
              ],
              "value": "Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <=\u00a02.1 versions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-591",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-591 Reflected XSS"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-04-28T16:08:28.479Z",
            "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
            "shortName": "Patchstack"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://patchstack.com/database/vulnerability/login-configurator/wordpress-login-configurator-plugin-2-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "WordPress Login Configurator Plugin <= 2.1 is vulnerable to Cross Site Scripting (XSS)",
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "assignerShortName": "Patchstack",
        "cveId": "CVE-2023-34175",
        "datePublished": "2023-08-30T13:39:25.858Z",
        "dateReserved": "2023-05-29T13:52:11.723Z",
        "dateUpdated": "2026-04-28T16:08:28.479Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }