CVE-2023-0096: Happyforms < 1.22.0 - Contributor+ Stored XSS
Published Feb 6, 2023
·Updated
The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Happyforms Happyforms WordPress<1.22.0
Event History
Feb 6, 2023
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-0096.
2
What is the severity rating of CVE-2023-0096?
CVE-2023-0096 has a severity rating of 5.4, which is classified as medium.
3
Which software is affected by CVE-2023-0096?
The Happyforms WordPress plugin before version 1.22.0 is affected by CVE-2023-0096.
4
What is the nature of the vulnerability in CVE-2023-0096?
CVE-2023-0096 is a vulnerability that allows users with the contributor role and above to perform Stored Cross-Site Scripting (XSS) attacks.
5
How can I fix CVE-2023-0096?
To fix CVE-2023-0096, you should update your Happyforms WordPress plugin to version 1.22.0 or newer.