CVE-2023-0084: Metform Elementor Contact Form Builder <= 3.1.2 - Unauthenticated Stored Cross-Site Scripting
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via text areas on forms in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page, which is the submissions page.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0084?
The severity of CVE-2023-0084 is high.
What is the vulnerability in the Metform Elementor Contact Form Builder plugin?
The vulnerability in the Metform Elementor Contact Form Builder plugin allows for Stored Cross-Site Scripting via text areas on forms.
Which versions of the Metform Elementor Contact Form Builder plugin are affected by CVE-2023-0084?
Versions up to and including 3.1.2 of the Metform Elementor Contact Form Builder plugin are affected by CVE-2023-0084.
How can an attacker exploit CVE-2023-0084?
An attacker can exploit CVE-2023-0084 by injecting arbitrary code through insufficient input sanitization and output escaping in text areas on forms.
Are authenticated credentials required for exploiting CVE-2023-0084?
No, CVE-2023-0084 can be exploited by unauthenticated attackers.