CVE-2023-5560: Lesterchan Wp-Useronline

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The WP-UserOnline WordPress plugin before 2.88.3 does not sanitise and escape the X-Forwarded-For header before outputting its content on the page, which allows unauthenticated users to perform Cross-Site Scripting attacks.

Affected products

  • Lesterchan Wp-Useronline: before 2.88.3 (fixed in 2.88.3)

Published 2023-11-27. Last modified 2026-06-17.