First published: Sat Jan 14 2023(Updated: )
Reflected Cross-Site Scripting (XSS) vulnerability in CRM Perks Forms – WordPress Form Builder <= 1.1.0 ver.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
CRM Perks CRM Perks Forms | <=1.1.0 |
Update to 1.1.1 or higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38467 is a Reflected Cross-Site Scripting (XSS) vulnerability in the CRM Perks Forms – WordPress Form Builder plugin version 1.1.0 and below.
CVE-2022-38467 has a severity rating of 6.1 (medium).
CRM Perks Forms – WordPress Form Builder plugin version 1.1.0 and below are affected by CVE-2022-38467.
The CWE for CVE-2022-38467 is CWE-79 (Improper Neutralization of Input During Web Page Generation).
To fix CVE-2022-38467, update the CRM Perks Forms – WordPress Form Builder plugin to version 1.2.0 or newer, which includes a patch for this vulnerability.