CVE-2022-38971: WordPress BuddyForms Plugin <= 2.7.5 is vulnerable to Cross Site Scripting (XSS)
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-38971?
CVE-2022-38971 is a stored Cross-Site Scripting (XSS) vulnerability in the ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin.
How severe is CVE-2022-38971?
CVE-2022-38971 has a severity rating of medium, with a CVSS score of 5.4.
How does CVE-2022-38971 affect software?
CVE-2022-38971 affects versions of the ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin up to and including 2.7.5.
What is the Common Weakness Enumeration (CWE) for CVE-2022-38971?
The Common Weakness Enumeration (CWE) for CVE-2022-38971 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Is there a patch or fix available for CVE-2022-38971?
Yes, a patch or fix is available for CVE-2022-38971. Please refer to the official reference for more information.