S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Mar 9, 2024

CVE-2023-30868 Scanner

CVE-2023-30868 scanner - Cross-Site Scripting vulnerability in CMS Tree Page View

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-30868
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jon Christopher CMS Tree Page View plugin <= 1.6.7 versions.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
CMS Tree Page Viewby Jon Christopher
n/a
Updated Aug 22, 2026View on NVD →
Detail

The CMS Tree Page View plugin for WordPress is designed to enhance the page management capabilities of WordPress sites. It allows users, especially administrators and content managers, to easily organize and sort pages and posts within a navigable tree structure. This plugin is particularly useful for websites with a large number of pages, providing a clear overview and improving site management efficiency. By simplifying the page viewing and sorting process, it aids in the content management workflow, making it an essential tool for website administrators looking for better content organization.

CVE-2023-30868 addresses a Reflected Cross-Site Scripting (XSS) vulnerability in the CMS Tree Page View plugin for WordPress versions up to 1.6.7. This vulnerability stems from improper sanitization of the post_type parameter, allowing attackers to inject malicious JavaScript code. When this code is accessed by users with administrative privileges, it executes within their browser. This security flaw exposes the site to potential malicious activities, including the theft of session cookies and personal data.

The vulnerability specifically lies in the handling of the post_type parameter by the plugin. It fails to properly escape user input, making it susceptible to an XSS attack when a specially crafted URL is accessed by an authenticated user with sufficient privileges. The injected script is executed in the context of the user's session, allowing an attacker to perform actions on behalf of the user or to steal information. This issue demonstrates the importance of validating and sanitizing all user inputs, especially in a widely used content management system like WordPress.

Exploitation of this XSS vulnerability can lead to several security issues, including unauthorized access to user sessions, redirection of users to malicious websites, and potential data theft. Attackers could leverage this vulnerability to gain control over an administrator's account, further compromising the website's integrity and privacy. The impact extends beyond individual users, potentially affecting all visitors to the site through the distribution of malware or phishing attempts.

Joining the S4E platform empowers you with advanced security scanning capabilities to identify vulnerabilities like CVE-2023-30868 in the CMS Tree Page View plugin. Our platform offers comprehensive vulnerability detection, detailed reports, and actionable remediation advice. By leveraging our expertise, you can enhance your website's security posture, protect against cyber threats, and maintain the trust of your users. Secure your digital assets and ensure the integrity of your online presence with our tailored security solutions.

 

References

Solution Advice
  1. Update the CMS Tree Page View plugin to version 1.6.7 or higher.
  2. Regularly update all WordPress plugins and themes to their latest versions.
  3. Utilize security plugins that provide web application firewall (WAF) capabilities to block XSS attacks.
  4. Conduct regular security audits of your website to identify and mitigate potential vulnerabilities.
  5. Educate users with administrative access about the dangers of XSS attacks and the importance of cautious link handling.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-30868 scanner - Cross-Site Scripting vulnerability in CMS Tree Page View | S4E