First published: Mon Mar 27 2023(Updated: )
The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Basix NEX-Forms – Ultimate Form Builder | <8.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-0272 is classified as high due to the potential for Stored Cross-Site Scripting vulnerabilities.
To fix CVE-2023-0272, update the NEX-Forms WordPress plugin to version 8.3.3 or later.
Versions of the NEX-Forms plugin prior to 8.3.3 are affected by CVE-2023-0272.
CVE-2023-0272 can be exploited to perform Stored Cross-Site Scripting attacks.
Users with the contributor role and above on a WordPress site using the vulnerable version of the NEX-Forms plugin are at risk from CVE-2023-0272.