CVE-2023-0424: Ms-Reviews Project Ms-Reviews
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
The MS-Reviews WordPress plugin through 1.5 does not sanitise and escape reviews, which could allow users any authenticated users, such as Subscribers to perform Stored Cross-Site Scripting attacks
Affected products
- Ms-Reviews Project Ms-Reviews: up to and including 1.5
Published 2023-04-24. Last modified 2026-06-17.