CVE-2023-3129General(kaizencoders / url_shortify)

LOWCVSS 4.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The URL Shortify WordPress plugin before 1.7.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • url_shortify

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
url_shortify

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-01: 108-01
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Bitcoin Meetup Ostschweiz 🇨🇭 #NoBIP110 Split@Peter_6_5
    General

    @cz_binance @TrustWallet Not Android, only Browser-Extension (Wasm) – CVE-2023-3129 and iOS problem 2018 (CVE-2024-23660).

    Post summary

    The tweet merely names two CVEs (Browser-Extension Wasm issue and an iOS 2018 problem) without providing any additional technical, exploit, or mitigation details.

    00010155
    437 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkaizencodersurl_shortify-wordpress-

Explore more