CVE-2022-38467: WordPress CRM Perks Forms Plugin <= 1.1.0 is vulnerable to Reflected Cross Site Scripting (XSS) vulnerability
Published Jan 14, 2023
·Updated
Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.
Affected Software
1 affected component
crmperks Crm Perks Forms Wordpress<=1.1.0
Remediation
Information
Update to 1.1.1 or higher version.
Event History
Jan 14, 2023
CVE Published
via MITRE·10:14 AM
Data Sourced
via MITRE·10:14 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38467?
CVE-2022-38467 is a Reflected Cross-Site Scripting (XSS) vulnerability in the CRM Perks Forms – WordPress Form Builder plugin version 1.1.0 and below.
2
How severe is CVE-2022-38467?
CVE-2022-38467 has a severity rating of 6.1 (medium).
3
Which software versions are affected by CVE-2022-38467?
CRM Perks Forms – WordPress Form Builder plugin version 1.1.0 and below are affected by CVE-2022-38467.
4
What is the Common Weakness Enumeration (CWE) for CVE-2022-38467?
The CWE for CVE-2022-38467 is CWE-79 (Improper Neutralization of Input During Web Page Generation).
5
How can I fix CVE-2022-38467?
To fix CVE-2022-38467, update the CRM Perks Forms – WordPress Form Builder plugin to version 1.2.0 or newer, which includes a patch for this vulnerability.