CVE-2023-5211: FATTURA24
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The Fattura24 WordPress plugin before 6.2.8 does not sanitize or escape the 'id' parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting vulnerability.
Affected products
- FATTURA24 FATTURA24: before 6.2.8 (fixed in 6.2.8)
Published 2023-10-31. Last modified 2026-06-17.