CVE-2022-23179: Contact Form & Lead Form Elementor Builder < 1.7.0 - Multiple Admin+ Stored Cross-Site Scripting
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.0 does not escape some of its form fields before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23179?
CVE-2022-23179 has a moderate severity rating due to potential Cross-Site Scripting vulnerabilities affecting high privilege users.
How do I fix CVE-2022-23179?
To fix CVE-2022-23179, upgrade the Contact Form & Lead Form Elementor Builder WordPress plugin to version 1.7.0 or later.
Who is affected by CVE-2022-23179?
Users of the Contact Form & Lead Form Elementor Builder plugin prior to version 1.7.0 are at risk of exploitation.
What type of vulnerability is CVE-2022-23179?
CVE-2022-23179 is a Cross-Site Scripting (XSS) vulnerability caused by improper escaping of form field attributes.
Can unprivileged users exploit CVE-2022-23179?
No, the vulnerability primarily affects high privilege users who can perform actions that lead to XSS attacks.