CVE-2023-28687

Reflected Cross-Site Scripting (XSS) vulnerability in multiple WordPress themes

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perfectwpthemes Glaze Blog Lite, themebeez Fascinate, themebeez Cream Blog, themebeez Cream Magazine allows Reflected XSS.This issue affects Glaze Blog Lite: from n/a through <= 1.1.4; Fascinate: from n/a through 1.0.8; Cream Blog: from n/a through 2.1.3; Cream Magazine: from n/a through 2.1.4.

Remediation

Solution:

  • Update Glaze Blog Lite to 1.1.5; Fascinate to 1.0.9; Cream Blog to 2.1.4; Cream Magazine to 2.1.5 or higher versions.

Category

7.1
CVSS
Severity: High
CVSS 3.1 •
EPSS 0.17%
Affected: perfectwpthemes Glaze Blog Lite
Affected: themebeez Fascinate
Affected: themebeez Cream Blog
Affected: themebeez Cream Magazine
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-28687?
CVE-2023-28687 has been scored as a high severity vulnerability.
How to fix CVE-2023-28687?
To fix CVE-2023-28687: Update Glaze Blog Lite to 1.1.5; Fascinate to 1.0.9; Cream Blog to 2.1.4; Cream Magazine to 2.1.5 or higher versions.
Is CVE-2023-28687 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2023-28687 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-28687?
CVE-2023-28687 affects perfectwpthemes Glaze Blog Lite, themebeez Fascinate, themebeez Cream Blog, themebeez Cream Magazine.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.