CVE-2023-2279
WordPress vulnerability analysis and mitigation

Overview

A stored Cross-Site Scripting (XSS) vulnerability was discovered in GitLab CE/EE affecting versions from 16.7 to 16.8.6, 16.9 before 16.9.4, and 16.10 before 16.10.2. The vulnerability exists in the autocomplete for issues references feature, which could allow attackers to perform unauthorized actions on behalf of victims (GitLab Release).

Technical details

The vulnerability is classified as high severity with a CVSS score of 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N). The issue allows attackers to inject malicious scripts through the autocomplete for issues references feature, which could then be stored and executed when viewed by other users (GitLab Release).

Impact

When exploited, this vulnerability enables attackers to hijack user sessions, steal sensitive data, and perform arbitrary actions on behalf of victims. The stored nature of the XSS makes it particularly dangerous as the malicious payload persists in the application (Security Online).

Mitigation and workarounds

GitLab has released patches to address this vulnerability. Users are strongly recommended to upgrade to versions 16.10.2, 16.9.4, or 16.8.6. GitLab.com has already been updated to the patched version. The vulnerability has been fixed in the latest release (GitLab Release).

Community reactions

The security community has emphasized the urgency of applying the patches, with security experts stressing the importance of immediate upgrades to protect against potential exploitation. The vulnerability was responsibly disclosed through GitLab's HackerOne bug bounty program by researcher yvvdwf (Security Online).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14030MEDIUM6.4
  • ai-feeds
NoYesDec 12, 2025
CVE-2025-12965MEDIUM6.4
  • magical-posts-display
NoYesDec 12, 2025
CVE-2025-14442MEDIUM5.3
  • secure-copy-content-protection
NoYesDec 12, 2025
CVE-2025-14065MEDIUM5.3
  • simple-bike-rental
NoYesDec 12, 2025
CVE-2025-14159MEDIUM4.3
  • secure-copy-content-protection
NoYesDec 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management