CVE-2020-10385: XSS
Published Mar 11, 2020
·Updated
A stored cross-site scripting (XSS) vulnerability exists in the WPForms Contact Form (aka wpforms-lite) plugin before 1.5.9 for WordPress.
Affected Software
1 affected component
WPForms Contact Form Wordpress<1.5.9
Event History
Mar 11, 2020
CVE Published
via MITRE·04:07 AM
Data Sourced
via MITRE·04:07 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2020-10385.
2
What is the severity of CVE-2020-10385?
The severity of CVE-2020-10385 is medium with a CVSS score of 5.4.
3
What is the affected software of CVE-2020-10385?
The affected software of CVE-2020-10385 is WPForms Contact Form plugin before version 1.5.9 for WordPress.
4
What is the CWE category of CVE-2020-10385?
The CWE category of CVE-2020-10385 is CWE-79 (Cross-Site Scripting).
5
How can I fix the vulnerability CVE-2020-10385?
To fix the vulnerability CVE-2020-10385, update the WPForms Contact Form plugin to version 1.5.9 or later.