S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-2272 Scanner

CVE-2023-2272 scanner - Cross-Site Scripting (XSS) vulnerability in Tiempo.com plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-2272
6.1
CVSS

The Tiempo.com WordPress plugin through 0.1.2 does not sanitise and escape the page parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Tiempo.com
0
Updated Aug 22, 2026View on NVD →
Detail

The Tiempo.com WordPress plugin is a tool used by website owners to display weather information on their website. It is particularly helpful for sites that deal with outdoor activities or provide local information to users. The plugin comes with a range of customization options that allow website owners to configure the appearance and behavior of the weather data.

However, the Tiempo.com WordPress plugin has been found to be vulnerable to a Reflected Cross-Site Scripting (XSS) exploit represented by the CVE-2023-2272 vulnerability code. This vulnerability occurs because the plugin does not properly sanitize and escape the "page" parameter, which can be manipulated by an attacker to inject malicious code into the website. The impact of this vulnerability is particularly severe for high privilege users such as the admin who have access to sensitive information.

This vulnerability can lead to serious consequences when exploited, as hackers could potentially access sensitive information by injecting malicious code into the website. They can also use stolen credentials or other methods to access administrative pages, thereby gaining control of the entire website. This can result in data breaches, defacement of the website, or even complete destruction of data.

In conclusion, the Tiempo.com WordPress plugin vulnerability poses a significant threat to website owners and their sensitive information. However, thanks to the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets, including the Tiempo.com plugin. By taking adequate precautions, website owners can ensure their security and protect their websites from such threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, WordPress website owners who use the Tiempo.com plugin can take the following precautions:

  • Update the plugin to the latest version
  • Install and enable a security plugin like Wordfence or Sucuri
  • Implement strict input validation and validation of user input
  • Enable PHP's native function php.ini config setting – "allow_url_fopen" to Off mode
  • Regularly scan the website for vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-2272 scanner - Cross-Site Scripting (XSS) vulnerability in Tiempo.com plugin for WordPress | S4E