LiveActive security incident?Get immediate response
CVE Record

CVE-2023-0072: WC Vendors Marketplace < 2.4.5 - Contributor+ Stored XSS

The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

MediumCVSS 5.4Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

A WordPress marketplace plugin could store unsafe script content through shortcode attributes. If a contributor-level user or higher can place affected shortcodes, visitors or administrators viewing the page could have browser actions influenced. The business risk is moderate because attacker access is required, but compromise can affect trust, sessions, and content integrity.

Executive priority

Prioritize routine but prompt remediation on affected WordPress commerce sites. This is not rated critical and requires authenticated content access, but stored XSS can damage customer trust and administrative sessions if contributor accounts are compromised.

Technical view

CVE-2023-0072 is a stored XSS flaw in WC Vendors Marketplace before 2.4.5. Some shortcode attributes were not validated and escaped before being rendered in pages or posts. CVSS 3.1 is 5.4 with low attack complexity, low privileges required, user interaction required, changed scope, and low confidentiality/integrity impact.

Likely exposure

Exposure is most likely on WordPress sites running WC Vendors Marketplace before 2.4.5, especially where contributor or higher accounts can create content containing plugin shortcodes. The supplied data does not indicate exposure for sites without the plugin or already updated to 2.4.5 or later.

Exploitation context

The bundle says this is not in CISA KEV. WPScan is tagged with exploit information, but the supplied sources do not establish active exploitation in the wild. Treat it as a plausible insider or compromised-account web risk, not confirmed mass exploitation.

Researcher notes

Key constraints are authenticated contributor-or-higher access and viewer interaction with a rendered page/post. The public record identifies shortcode attribute validation and escaping as the root issue. The provided affected-product metadata is sparse, so rely on plugin presence and version before 2.4.5 for exposure decisions.

Mitigation direction

  • Update WC Vendors Marketplace to version 2.4.5 or later.
  • Restrict contributor and author access until affected sites are updated.
  • Review pages and posts containing WC Vendors shortcodes for suspicious attributes.
  • Check plugin vendor guidance for any additional cleanup or hardening advice.

Validation and detection

  • Inventory WordPress sites using WC Vendors Marketplace and record plugin versions.
  • Confirm vulnerable sites are no longer running versions before 2.4.5.
  • Review roles allowed to create or edit shortcode-bearing content.
  • Inspect existing WC Vendors shortcode usage for unexpected script-like content.
  • Verify updated shortcode output is safely escaped in staging.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-79: User-session and phishing behavior lookup

Client-side and session-facing weaknesses should be reviewed alongside initial-access and user-execution behaviors. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2023-0072 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.4 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.4CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N2.32.7Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

5.4Medium
CVSS 3.1 vector shape for CVE-2023-0072Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
UnknownWC Vendors Marketplace0unaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.