First published: Tue Sep 10 2019(Updated: )
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
nCrafts FormCraft | <=3.2.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18600 is considered a medium-severity stored Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2017-18600, upgrade the formcraft3 plugin to version 3.4 or later.
CVE-2017-18600 affects formcraft3 plugin versions prior to 3.4.
CVE-2017-18600 is a stored XSS vulnerability affecting WordPress sites using the formcraft3 plugin.
Yes, CVE-2017-18600 can be easily exploited by attackers to execute malicious scripts within the context of the user's session.