CVE-2023-47786
About
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LayerSlider plugin <= 7.7.9 versions.
Rainforest analyst review
LayerSlider versions up to and including 7.7.9 carry a cross-site scripting flaw: unsanitized input reaches a page and executes as script in a visitor's browser. Because this is a WordPress plugin, the payload runs in the context of the affected site, and with a scope change it can reach beyond the immediate component. Exploitation needs a low-privileged account and a user to interact, so it's conditional rather than a direct server compromise.
The measured read is that stored or reflected XSS in a plugin is a session-and-content threat, not an unauthenticated takeover. Delivered against an administrator it can hijack privileged actions; against ordinary visitors it enables defacement, redirects, or credential theft in the browser. That's meaningful, but it sits below the plugin file-upload and injection bugs that give attackers code on the server with no interaction at all.
Our angle is inventory tied to proportionate ranking. WordPress plugins are hard to track because they're installed per-site by site owners, so we enumerate where LayerSlider runs and at what version against the 7.7.9 ceiling — then hold it at its medium rating rather than escalating. Detection of anomalous script in plugin-rendered output and prompt updating close it out without displacing the higher-severity items in the queue.
References
Related CVEs
Frequently asked questions
What is CVE-2023-47786?
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LayerSlider plugin <= 7.7.9 versions.
How severe is CVE-2023-47786?
CVE-2023-47786 carries a CVSS 3.1 base score of 6.5, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 67 out of 100, in the elevated band.
How is CVE-2023-47786 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L): attack vector Network, attack complexity Low, privileges required Low, user interaction Required. Impact on confidentiality Low, integrity Low and availability Low.
Which products are affected by CVE-2023-47786?
Public advisories list the following as affected: layerslider. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-47786?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
