CVE-2023-0272: NEX-Forms < 8.3.3 - Contributor+ Stored XSS
The NEX-Forms WordPress plugin before 8.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0272?
The severity of CVE-2023-0272 is classified as high due to the potential for Stored Cross-Site Scripting vulnerabilities.
How do I fix CVE-2023-0272?
To fix CVE-2023-0272, update the NEX-Forms WordPress plugin to version 8.3.3 or later.
Which versions of the NEX-Forms plugin are affected by CVE-2023-0272?
Versions of the NEX-Forms plugin prior to 8.3.3 are affected by CVE-2023-0272.
What type of attack can be executed due to CVE-2023-0272?
CVE-2023-0272 can be exploited to perform Stored Cross-Site Scripting attacks.
Who is vulnerable to CVE-2023-0272?
Users with the contributor role and above on a WordPress site using the vulnerable version of the NEX-Forms plugin are at risk from CVE-2023-0272.